首页> 外文会议>International Conference on Signal Processing and Integrated Networks >DNS traffic analysis for malicious domains detection
【24h】

DNS traffic analysis for malicious domains detection

机译:DNS流量分析以检测恶意域

获取原文

摘要

The web has become the medium of choice for people to search for information, conduct business, and enjoy entertainment. At the same time, the web has also become the primary platform used by miscreants to attack users. For example, drive-by-download attacks, which could be through malicious domains, are a popular choice among bot herders to grow their botnets. In this paper we present our methodology for detecting any connection to malicious domain. Our detection method is based on a blacklist of malicious domains. We process the network traffic, particularly DNS traffic. We analyze all DNS requests and match the query with the blacklist. The blacklist of malicious domains is updated automatically and the detection is in the real time. We applied our methodology on a packet capture (pcap) file which contains traffic to malicious domains and we proved that our methodology can successfully detect the connections to malicious domains. We also applied our methodology on campus live traffic and showed that it can detect malicious domain connections in the real time.
机译:网络已经成为人们搜索信息,开展业务和享受娱乐的首选媒介。同时,网络也已成为不法分子攻击用户的主要平台。例如,可能通过恶意域进行的按下载驱动攻击是僵尸网络牧民发展僵尸网络的一种流行选择。在本文中,我们介绍了用于检测与恶意域的任何连接的方法。我们的检测方法基于恶意域黑名单。我们处理网络流量,尤其是DNS流量。我们分析所有DNS请求,并将查询与黑名单进行匹配。恶意域黑名单会自动更新,并且可以实时检测到。我们将我们的方法应用于包含恶意域流量的数据包捕获(pcap)文件,并且证明了我们的方法可以成功检测到恶意域的连接。我们还将我们的方法应用于校园实时流量,并表明它可以实时检测恶意域连接。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号