Malware authors evading detection via domain generation algorithms->
Submitted
by
alphadogg
alphadogg writes "Malware authors are increasingly adopting flexible domain generation algorithms (DGAs) in order to evade detection and prevent their botnets from being shut down by security researchers or law enforcement agencies. DGAs are generally used as a fallback mechanism for sending instructions to infected computers when the hard-coded command and control servers become unavailable. The algorithms generate a list of unique pseudo-random domain names every day. Clients in a botnet attempt to connect to them and receive commands when the primary servers can't be reached. Knowing the algorithm allows malware authors to predict which domain names infected computers will attempt to access on a certain date, so they can register one of them in advance."
Link to Original Source
Link to Original Source