IEICE Technical Committee Submission System
Conference Paper's Information
Online Proceedings
[Sign in]
Tech. Rep. Archives
 Go Top Page Go Previous   [Japanese] / [English] 

Paper Abstract and Keywords
Presentation 2020-03-02 14:05
Implementation and Evaluation of Detection and Blocking System against DGA-based Bot by Focusing on NXDOMAIN Responses
Yuki Iuchi (Hokkaido Univ.), Yong Jin, Hikaru Ichise (Tokyo Tech), Katsuyoshi Iida, Yoshiaki Takai (Hokkaido Univ.) SITE2019-89 IA2019-67
Abstract (in Japanese) (See Japanese page) 
(in English) Recently, security attacks caused by a bot have been widely spreading. In this research, we aim to detect and block Domain Generation Algorithms (DGAs) based bots by focusing on special characteristics of DNS domain name resolutions for Command & Control (C&C) servers. The DGAs generate domain names using pseudo random functions with the seed of the current time of day, the trend keywords in SNS, etc. The attackers register a part of the generated domain names on the authoritative DNS server in order to make the bots find out the C&C server. The generated domain names are difficult to be estimated by other individuals than the attackers therefore the network administrators can hardly identify malicious DNS domain name resolutions. To deal with this issue, we focus on the characteristic of DGAs, namely NXDOMAIN responses were frequently received because many generated domain names have not been registered on the authoritative DNS server. In this paper, we design and implement a system to detect and block the malicious DNS domain name resolutions by analyzing the NXDOMAIN responses, which are received when the bots try to find out the C&C servers. By using the prototype system, we also evaluate its effectiveness with multiple DGAs.
Keyword (in Japanese) (See Japanese page) 
(in English) Bot / Botnet / DNS / DGA / NXDOMAIN / SDN / /  
Reference Info. IEICE Tech. Rep., vol. 119, no. 435, IA2019-67, pp. 7-12, March 2020.
Paper # IA2019-67 
Date of Issue 2020-02-24 (SITE, IA) 
ISSN Print edition: ISSN 0913-5685  Online edition: ISSN 2432-6380
All rights are reserved and no part of this publication may be reproduced or transmitted in any form or by any means, electronic or mechanical, including photocopy, recording, or any information storage and retrieval system, without permission in writing from the publisher. Notwithstanding, instructors are permitted to photocopy isolated articles for noncommercial classroom use without fee. (License No.: 10GA0019/12GB0052/13GB0056/17GB0034/18GB0034)
Download PDF SITE2019-89 IA2019-67

Conference Information
Committee IA SITE IPSJ-IOT  
Conference Date 2020-03-02 - 2020-03-03 
Place (in Japanese) (See Japanese page) 
Place (in English) Online 
Topics (in Japanese) (See Japanese page) 
Topics (in English) Internet and Information Ethics Education, etc. 
Paper Information
Registration To IA 
Conference Code 2020-03-IA-SITE-IOT 
Language Japanese 
Title (in Japanese) (See Japanese page) 
Sub Title (in Japanese) (See Japanese page) 
Title (in English) Implementation and Evaluation of Detection and Blocking System against DGA-based Bot by Focusing on NXDOMAIN Responses 
Sub Title (in English)  
Keyword(1) Bot  
Keyword(2) Botnet  
Keyword(3) DNS  
Keyword(4) DGA  
Keyword(5) NXDOMAIN  
Keyword(6) SDN  
1st Author's Name Yuki Iuchi  
1st Author's Affiliation Hokkaido University (Hokkaido Univ.)
2nd Author's Name Yong Jin  
2nd Author's Affiliation Tokyo Institute of Technology (Tokyo Tech)
3rd Author's Name Hikaru Ichise  
3rd Author's Affiliation Tokyo Institute of Technology (Tokyo Tech)
4th Author's Name Katsuyoshi Iida  
4th Author's Affiliation Hokkaido University (Hokkaido Univ.)
5th Author's Name Yoshiaki Takai  
5th Author's Affiliation Hokkaido University (Hokkaido Univ.)
6th Author's Name  
6th Author's Affiliation ()
7th Author's Name  
7th Author's Affiliation ()
8th Author's Name  
8th Author's Affiliation ()
9th Author's Name  
9th Author's Affiliation ()
10th Author's Name  
10th Author's Affiliation ()
11th Author's Name  
11th Author's Affiliation ()
12th Author's Name  
12th Author's Affiliation ()
13th Author's Name  
13th Author's Affiliation ()
14th Author's Name  
14th Author's Affiliation ()
15th Author's Name  
15th Author's Affiliation ()
16th Author's Name  
16th Author's Affiliation ()
17th Author's Name  
17th Author's Affiliation ()
18th Author's Name  
18th Author's Affiliation ()
19th Author's Name  
19th Author's Affiliation ()
20th Author's Name  
20th Author's Affiliation ()
Speaker Author-1 
Date Time 2020-03-02 14:05:00 
Presentation Time 25 minutes 
Registration for IA 
Paper # SITE2019-89, IA2019-67 
Volume (vol) vol.119 
Number (no) no.434(SITE), no.435(IA) 
Page pp.7-12 
Date of Issue 2020-02-24 (SITE, IA) 

[Return to Top Page]

[Return to IEICE Web Page]

The Institute of Electronics, Information and Communication Engineers (IEICE), Japan