【24h】

Investigating DNS traffic anomalies for malicious activities

机译:调查DNS交通异常进行恶意活动

获取原文

摘要

The Domain Name System (DNS) is one of the critical components of modern Internet networking. Proper Internet functions (such as mail delivery, web browsing and so on) are typically not possible without the use of DNS. However with the growth and commercialization of global networking, this protocol is often abused for malicious purposes which negatively impact the security of Internet users. In this paper we perform security data analysis of DNS traffic at large scale for a prolonged period of time. In order to do this, we developed DNSPacketlizer, a DNS traffic analysis tool and deployed it at a mid-scale Internet Service Provider (ISP) for a period of six months. The findings presented in this paper demonstrate persistent abuse of the protocol by Botnet herders and antivirus software vendors for covert communication. Other suspicious or potentially malicious activities in DNS traffic are also discussed. The material of this paper has been cleared through the affiliations of the authors.
机译:域名系统(DNS)是现代互联网网络的关键组件之一。在不使用DNS的情况下,通常不可能使用适当的Internet函数(例如邮件传递,Web浏览等)。然而,随着全球网络的增长和商业化,该协议通常被滥用,因为恶意目的对互联网用户的安全产生负面影响。在本文中,我们在大规模的时间内对DNS流量进行安全数据分析。为此,我们开发了DNSPacketlizer,DNS流量分析工具,并在中间互联网服务提供商(ISP)中部署了六个月的时间。本文提出的调查结果展示了僵尸网络牧民和防病毒软件供应商的持续滥用议定书,以封闭通信。还讨论了DNS流量的其他可疑或潜在的恶意活动。本文的材料已通过作者的附属方式清除。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号