Sažetak
Today, networks of compromised computers, known as botnets, pose a major threat to computer security. These networks serve websites that are used for communication between bots and for further expansion of the network, where they fraudulently collect information or carry out their scams. Fraud is carried out by imitating existing websites, i.e. by referring to a known business transaction of the user, e.g. the websites of the Tax Administration or the Ministry of the Interior. Blocking such domains can significantly limit the spread of botnets. There are known features that can be used to detect such domains. Many of these known features are based on forensic linguistic methods. In this paper, we will focus on one of the known features of using numbers in domain names. By analyzing available detected compromised domains as well as known valid domains, we determine the applicability of such a feature.
Ključne riječi
Botnet detection, forensic linguistic