Investigating DNS traffic anomalies for malicious activities

Fyodor Yarochkin, Vladimir Kropotov, Yennun Huang, Guo Kai Ni, Sy Yen Kuo, Ing Yi Chen

研究成果: 圖書/報告稿件的類型會議稿件同行評審

4 引文 斯高帕斯(Scopus)

摘要

The Domain Name System (DNS) is one of the critical components of modern Internet networking. Proper Internet functions (such as mail delivery, web browsing and so on) are typically not possible without the use of DNS. However with the growth and commercialization of global networking, this protocol is often abused for malicious purposes which negatively impacts the security of Internet users. In this paper we perform security data analysis of DNS traffic at large scale for a prolonged period of time. In order to do this, we developed DNSPacketlizer, a DNS traffic analysis tool and deployed it at a mid-scale Internet Service Provider (ISP) for a period of six months. The findings presented in this paper demonstrate persistent abuse of the protocol by Botnet herders and antivirus software vendors for covert communication. Other suspicious or potentially malicious activities in DNS traffic are also discussed.

原文英語
主出版物標題2013 43rd Annual IEEE/IFIP Conference on Dependable Systems and Networks Workshop, DSN-W 2013
DOIs
出版狀態已出版 - 2013
對外發佈
事件2013 43rd Annual IEEE/IFIP Conference on Dependable Systems and Networks Workshop, DSN-W 2013 - Budapest, 匈牙利
持續時間: 24 06 201327 06 2013

出版系列

名字Proceedings of the International Conference on Dependable Systems and Networks

Conference

Conference2013 43rd Annual IEEE/IFIP Conference on Dependable Systems and Networks Workshop, DSN-W 2013
國家/地區匈牙利
城市Budapest
期間24/06/1327/06/13

指紋

深入研究「Investigating DNS traffic anomalies for malicious activities」主題。共同形成了獨特的指紋。

引用此