首页> 外文会议>2011 Network and distributed system security symposium >EXPOSURE: Finding Malicious Domains Using Passive DNS Analysis
【24h】

EXPOSURE: Finding Malicious Domains Using Passive DNS Analysis

机译:暴露:使用被动DNS分析查找恶意域

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

The domain name service (DNS) plays an important role in the operation of the Internet, providing a two-way mapping between domain names and their numerical identifiers. Given its fundamental role, it is not surprising that a wide variety of malicious activities involve the domain name service in one way or another. For example, hots resolve DNS names to locate their command and control servers, and spam mails contain URLs that link to domains that resolve to scam servers. Thus, it seems beneficial to monitor the use of the DNS system for signs that indicate that a certain name is used as part of a malicious operation. In this paper, we introduce EXPOSURE, a system that employs large-scale, passive DNS analysis techniques to detect domains that are involved in malicious activity. We use 15 features that we extract from the DNS traffic that allow us to characterize different properties of DNS names and the ways that they are queried. Our experiments with a large, real-world data set consisting of 100 billion DNS requests, and a real-life deployment for two weeks in an ISP show that our approach is scalable and that we are able to automatically identify unknown malicious domains that are misused in a variety of malicious activity (such as for botnet command and control, spamming, and phishing).
机译:域名服务(DNS)在Internet的运行中起着重要作用,它提供了域名及其数字标识符之间的双向映射。鉴于其基本作用,各种各样的恶意活动以一种或另一种方式涉及域名服务也就不足为奇了。例如,热点解析DNS名称以定位其命令和控制服务器,垃圾邮件包含链接到解析为欺诈服务器的域的URL。因此,监视DNS系统的使用是否有迹象表明某些名称被用作恶意操作的一部分似乎是有益的。在本文中,我们介绍了EXPOSURE,该系统采用大规模,被动DNS分析技术来检测与恶意活动有关的域。我们使用从DNS流量中提取的15个功能,这些功能使我们能够表征DNS名称的不同属性以及查询它们的方式。我们对包含1000亿个DNS请求的大型真实数据集进行的实验以及在ISP中进行为期两周的实际部署表明,我们的方法具有可扩展性,并且能够自动识别被滥用的未知恶意域各种恶意活动(例如,僵尸网络命令和控制,垃圾邮件和网络钓鱼)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号