Adversary uses malware to attack users’ computer in order to compromise them. The malware can take control of the compromised machines and turn compromised machines into remotely controlled bots. A bot is a machine that is compromised by a malware. The stealthy malware agent, running on the compromised machine, enables the bot to be remotely controlled by the adversary (Botmaster) via a Command and Control (C&C) Server. A botnet is a network of compromised machines (bots) under control of a Command and Control (C&C) Server. Each individual compromised machine in a botnet is referred to as a bot.

After successful malware infection the malware report back to the command-and-control (C&C) server to get new command and updates from the adversary.


Fast flux is a DNS technique which involves frequent and rapid changing of the IP addresses associated with a Fully Qualified Domain Name (FQDN) by using a network of compromised hosts (Bots) acting as proxies. Fast-flux technique is employed by the adversary to evade C&C server detection and IP based Blacklisting by constantly changing the IP addresses of the C&C server domain within very short period of time.

In a Fast flux network adversary configures a number of bots from his controlled botnet to serve as proxies to the C&C server. These bots are known as flux-agents and they work as the redirectors. Fast flux network provides a constantly changing proxy layer between the malware infected bots and the C&C server of a botnet.

Types of Fast Flux networks:

  1. Single Flux Networks
  2. Double Flux Networks