Viruses can be detected by analyzing DNS traffic.
Computer security experts have proposed a new way to detect viruses in local networks.
Viruses often link to a specific website that controls their operation. This website launches the virus and receives the results of the malware's activity.
Such sites are often shut down by law enforcement agencies, so hackers periodically change the names of sites using a special algorithm built into viruses.
Thus, DNS traffic analysis, in particular frequent requests to special sites with strange domain names, such as joftvvtvmx.org, ejfjyd.mooo.com, and mnkzof.dyndns.org, will allow us to draw conclusions about the presence of virus activity.
The developers have already created an application that can identify dangerous websites and tested its operation on more than 500 domain names.