Por favor, use este identificador para citar o enlazar este ítem:
https://dspace.ucuenca.edu.ec/handle/123456789/42999Registro completo de metadatos
| Campo DC | Valor | Lengua/Idioma |
|---|---|---|
| dc.contributor.author | Astudillo Salinas, Darwin Fabian | |
| dc.contributor.author | Quezada Pauta, Vicente Geovanny | |
| dc.date.accessioned | 2023-10-03T14:13:03Z | - |
| dc.date.available | 2023-10-03T14:13:03Z | - |
| dc.date.issued | 2023 | |
| dc.identifier.issn | 1389-1286 | |
| dc.identifier.uri | http://dspace.ucuenca.edu.ec/handle/123456789/42999 | - |
| dc.identifier.uri | https://www.scopus.com/record/display.uri?eid=2-s2.0-85151397842&origin=resultslist&sort=plf-f&src=s&sid=fabc4659b4b8ab2a3a09d48deb0ba195&sot=b&sdt=b&s=TITLE-ABS-KEY%28Real-time+bot+infection+detection+system+using+DNS+fingerprinting+and+machine-learning%29&sl=101&sessionSearchId=fabc4659b4b8ab2a3a09d48deb0ba195 | |
| dc.description.abstract | In today's cyberattacks, botnets are used as an advanced technique to generate sophisticated and coordinated attacks. Infected systems connect to a command and control (C&C) server to receive commands and attack. Thus, detecting infected hosts makes it possible to protect the network's resources and prevent them from illicit activities toward third parties. This research elaborates on the design, implementation, and results of a bot infection detection system based on Domain Name System (DNS) traffic events for a network corporation. An infection detection feasibility analysis is performed by creating fingerprints. The traces are generated from a numerical analysis of 13 attributes. These attributes are obtained from the DNS logs of a DNS server. It looks for fingerprint anomalies using Isolation Forest to label a host as infected or not. In addition, on the traces cataloged as anomalous, a search will be carried out for queries to domains generated by Domain Generation Algorithms (DGA). Then, Random Forest generates a model that detects future bot infections on hosts. The devised system integrates the ELK stack and Python. This integration facilitates the management, transformation, and storage of events, generation of fingerprints, machine learning application, and analysis of fingerprint classification results with a precision greater than 99%. | |
| dc.language.iso | es_ES | |
| dc.source | Computer Networks | |
| dc.subject | Bot detection | |
| dc.subject | ELK stack | |
| dc.subject | Anomaly detection | |
| dc.subject | Random forests | |
| dc.subject | Machine learning | |
| dc.subject | Isolation forests | |
| dc.subject | DNS-based bot detection | |
| dc.subject | Botnet | |
| dc.title | Real-time bot infection detection system using DNS fingerprinting and machine-learning | |
| dc.type | ARTÍCULO | |
| dc.ucuenca.idautor | 0103907036 | |
| dc.ucuenca.idautor | 0106338320 | |
| dc.identifier.doi | 10.1016/j.comnet.2023.109725 | |
| dc.ucuenca.version | Versión publicada | |
| dc.ucuenca.areaconocimientounescoamplio | 06 - Información y Comunicación (TIC) | |
| dc.ucuenca.afiliacion | Quezada, V., Universidad de Cuenca, Cuenca, Ecuador | |
| dc.ucuenca.afiliacion | Astudillo, D., Universidad de Cuenca, Cuenca, Ecuador | |
| dc.ucuenca.correspondencia | Quezada Pauta, Vicente Geovanny, vicente.quezada@ucuenca.edu.ec | |
| dc.ucuenca.volumen | Volume 228 | |
| dc.ucuenca.indicebibliografico | SCOPUS | |
| dc.ucuenca.factorimpacto | 1.63 | |
| dc.ucuenca.cuartil | Q1 | |
| dc.ucuenca.numerocitaciones | 0 | |
| dc.ucuenca.areaconocimientofrascatiamplio | 2. Ingeniería y Tecnología | |
| dc.ucuenca.areaconocimientofrascatiespecifico | 2.11 Otras Ingenierias y Tecnologías | |
| dc.ucuenca.areaconocimientofrascatidetallado | 2.11.2 Otras Ingenierias y Tecnologías | |
| dc.ucuenca.areaconocimientounescoespecifico | 061 - Información y Comunicación (TIC) | |
| dc.ucuenca.areaconocimientounescodetallado | 0613 - Software y Desarrollo y Análisis de Aplicativos | |
| dc.ucuenca.urifuente | https://www.sciencedirect.com/journal/computer-networks | |
| Aparece en las colecciones: | Artículos | |
Ficheros en este ítem:
| Fichero | Tamaño | Formato | |
|---|---|---|---|
| documento.pdf | 2.36 MB | Adobe PDF | Visualizar/Abrir |
Este ítem está protegido por copyright original |
Los ítems de DSpace están protegidos por copyright, con todos los derechos reservados, a menos que se indique lo contrario.
Centro de Documentacion Regional "Juan Bautista Vázquez" | ||||||||||
| ||||||||||
