*Cheran College of Engineering, Karur, Tamilnadu, India
**Jay Shriram Group of Institutions, Tirupur, Tamilnadu, India
Online published on 14 October, 2016.
Domain Name Server (DNS) is used to maintain the IP address of each domain in the internet. The botnets attacks the DNS to resolve the actual IP address to their own IP address or to position their Command and Control servers to malfunction the website. Detecting these types of attacks using passive monitoring of DNS queries is an efficient technique. In this work, on analysing a number of behaviours of this IP queries we have detected the botnets and their C & C traffic in the DNS. The time based analysis, in bound and out bound analysis and Hash based probing detects the botnet in an efficient way.