Machine Learning on DNS Data to Discover Security Threats

Webroot, Inc. Computer Science, 2017-18

Liaison(s): Dave Krich, Kiran Kumar, Hal Lonas, Trung Tran, Cathy Yang
Advisor(s): Lisa Kaczmarczyk
Students(s): Julia McCarthy (PM), Anthony Romm, Reiko Tojo, Danny Wang

In this project, the goals were to aggregate DNS-level data, apply machine learning approaches to identify command and control (C&C) botnets through automated analysis of live traffic patterns, and construct a website for dynamic visualization of threats. Visualizations help the user pinpoint where botnet attacks are coming from, identify geographic hotspots for botnet activity, and find out who is at risk for infection.