{"id":12435,"date":"2023-06-12T08:27:44","date_gmt":"2023-06-12T08:27:44","guid":{"rendered":"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/?post_type=session&#038;p=12435"},"modified":"2024-07-31T01:39:03","modified_gmt":"2024-07-31T01:39:03","slug":"commsec-detecting-botnets-via-dns-traffic-analysis-using-machine-learning","status":"publish","type":"session","link":"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/session\/commsec-detecting-botnets-via-dns-traffic-analysis-using-machine-learning\/","title":{"rendered":"COMMSEC: Detecting Botnets via DNS Traffic Analysis Using Machine Learning"},"content":{"rendered":"<p style=\"text-align: justify;\">Botnets represent a substantial cyber threat, frequently employed in illicit activities such as Distributed Denial of Service (DDoS) attacks and data theft. These botnets adeptly evade detection through the continual advancement of techniques designed to obscure their command and control (C&amp;C) servers. This study introduces a methodology for the detection of botnet-infected devices via the analysis of Domain Name System (DNS) traffic.<\/p>\n<p>The proposed approach distinguishes between domain names generated by botnet algorithms and those created by humans, utilizing an integration of natural language processing principles augmented by a whitelist. Furthermore, this research includes a comprehensive evaluation of the performance and effectiveness of the Random Forest model, identifying critical performance parameters essential for anomaly detection in DNS traffic. The analysis is conducted leveraging multicore CPU processing to enhance detection capabilities.<\/p>\n","protected":false},"template":"","class_list":["post-12435","session","type-session","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>COMMSEC: Detecting Botnets via DNS Traffic Analysis Using Machine Learning - HITBSecConf2024 - Bangkok<\/title>\n<meta name=\"description\" content=\"This study introduces a methodology for the detection of botnet-infected devices via the analysis of Domain Name System (DNS) traffic.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/session\/commsec-detecting-botnets-via-dns-traffic-analysis-using-machine-learning\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Detecting Botnets via DNS Traffic Analysis Using Machine Learning\" \/>\n<meta property=\"og:description\" content=\"This study introduces a methodology for the detection of botnet-infected devices via the analysis of Domain Name System (DNS) traffic.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/session\/commsec-detecting-botnets-via-dns-traffic-analysis-using-machine-learning\/\" \/>\n<meta property=\"og:site_name\" content=\"HITBSecConf2024 - Bangkok\" \/>\n<meta property=\"article:modified_time\" content=\"2024-07-31T01:39:03+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/wp-content\/uploads\/sites\/22\/2024\/07\/korrawit.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"300\" \/>\n\t<meta property=\"og:image:height\" content=\"300\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Detecting Botnets via DNS Traffic Analysis Using Machine Learning\" \/>\n<meta name=\"twitter:description\" content=\"This study introduces a methodology for the detection of botnet-infected devices via the analysis of Domain Name System (DNS) traffic.\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/wp-content\/uploads\/sites\/22\/2024\/07\/korrawit.jpg\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/session\/commsec-detecting-botnets-via-dns-traffic-analysis-using-machine-learning\/\",\"url\":\"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/session\/commsec-detecting-botnets-via-dns-traffic-analysis-using-machine-learning\/\",\"name\":\"COMMSEC: Detecting Botnets via DNS Traffic Analysis Using Machine Learning - HITBSecConf2024 - Bangkok\",\"isPartOf\":{\"@id\":\"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/#website\"},\"datePublished\":\"2023-06-12T08:27:44+00:00\",\"dateModified\":\"2024-07-31T01:39:03+00:00\",\"description\":\"This study introduces a methodology for the detection of botnet-infected devices via the analysis of Domain Name System (DNS) traffic.\",\"breadcrumb\":{\"@id\":\"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/session\/commsec-detecting-botnets-via-dns-traffic-analysis-using-machine-learning\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/session\/commsec-detecting-botnets-via-dns-traffic-analysis-using-machine-learning\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/session\/commsec-detecting-botnets-via-dns-traffic-analysis-using-machine-learning\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Session\",\"item\":\"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/session\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"COMMSEC: Detecting Botnets via DNS Traffic Analysis Using Machine Learning\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/#website\",\"url\":\"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/\",\"name\":\"HITBSecConf2024 - Bangkok\",\"description\":\"August 26 - 30 @ InterContinental\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"COMMSEC: Detecting Botnets via DNS Traffic Analysis Using Machine Learning - HITBSecConf2024 - Bangkok","description":"This study introduces a methodology for the detection of botnet-infected devices via the analysis of Domain Name System (DNS) traffic.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/session\/commsec-detecting-botnets-via-dns-traffic-analysis-using-machine-learning\/","og_locale":"en_US","og_type":"article","og_title":"Detecting Botnets via DNS Traffic Analysis Using Machine Learning","og_description":"This study introduces a methodology for the detection of botnet-infected devices via the analysis of Domain Name System (DNS) traffic.","og_url":"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/session\/commsec-detecting-botnets-via-dns-traffic-analysis-using-machine-learning\/","og_site_name":"HITBSecConf2024 - Bangkok","article_modified_time":"2024-07-31T01:39:03+00:00","og_image":[{"width":300,"height":300,"url":"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/wp-content\/uploads\/sites\/22\/2024\/07\/korrawit.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_title":"Detecting Botnets via DNS Traffic Analysis Using Machine Learning","twitter_description":"This study introduces a methodology for the detection of botnet-infected devices via the analysis of Domain Name System (DNS) traffic.","twitter_image":"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/wp-content\/uploads\/sites\/22\/2024\/07\/korrawit.jpg","twitter_misc":{"Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/session\/commsec-detecting-botnets-via-dns-traffic-analysis-using-machine-learning\/","url":"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/session\/commsec-detecting-botnets-via-dns-traffic-analysis-using-machine-learning\/","name":"COMMSEC: Detecting Botnets via DNS Traffic Analysis Using Machine Learning - HITBSecConf2024 - Bangkok","isPartOf":{"@id":"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/#website"},"datePublished":"2023-06-12T08:27:44+00:00","dateModified":"2024-07-31T01:39:03+00:00","description":"This study introduces a methodology for the detection of botnet-infected devices via the analysis of Domain Name System (DNS) traffic.","breadcrumb":{"@id":"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/session\/commsec-detecting-botnets-via-dns-traffic-analysis-using-machine-learning\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/session\/commsec-detecting-botnets-via-dns-traffic-analysis-using-machine-learning\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/session\/commsec-detecting-botnets-via-dns-traffic-analysis-using-machine-learning\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/"},{"@type":"ListItem","position":2,"name":"Session","item":"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/session\/"},{"@type":"ListItem","position":3,"name":"COMMSEC: Detecting Botnets via DNS Traffic Analysis Using Machine Learning"}]},{"@type":"WebSite","@id":"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/#website","url":"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/","name":"HITBSecConf2024 - Bangkok","description":"August 26 - 30 @ InterContinental","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/wp-json\/wp\/v2\/session\/12435"}],"collection":[{"href":"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/wp-json\/wp\/v2\/session"}],"about":[{"href":"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/wp-json\/wp\/v2\/types\/session"}],"wp:attachment":[{"href":"https:\/\/conference.hitb.org\/hitbsecconf2024bkk\/wp-json\/wp\/v2\/media?parent=12435"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}