主催: 電気・情報関係学会九州支部連合大会委員会
会議名: 平成29年度電気・情報関係学会九州支部連合大会
回次: 70
開催地: 琉球大学
開催日: 2017/09/27 - 2017/09/28
Bot acquires a C and C server's IP address from an FQDN using DNS protocol. A Domain blacklist bans name resolution of C and C server on a cache DNS server. Moreover, it is possible to prevent communication between bot and C and C server. Several bots avoid domain blacklist using random FQDN such as DGA. However, DGA generates a large number of DNS queries. Almost queries will return NXDomain answers. Therefore, we analyze the number of NXDomain answers per IP address at regular intervals. As a result, we found abnormal clients. The client has been generating many queries that look like a DGA.