...
首页> 外文期刊>Neurocomputing >Visualizing and characterizing DNS lookup behaviors via log-mining
【24h】

Visualizing and characterizing DNS lookup behaviors via log-mining

机译:通过日志挖掘可视化和表征DNS查找行为

获取原文
获取原文并翻译 | 示例
           

摘要

The Domain Name System (DNS) is a critical Internet service, which translates easily memorized domain names to numerical IP addresses for locating computer resources and services. In this paper, we try to explore the behaviors of DNS lookup by mining DNS logs from three primary DNS servers in a large university campus network in China. Our dataset is made up of two parts, namely DNS query logs and messages received or send by DNS servers. Firstly, through analyzing these DNS query logs, we are able to understand the overall trend of users' surfing. For dealing with huge DNS dataset, we introduce an algorithm we call DNSReduce, which can be used to dig out top 10 client IP addresses and top 10 destination domain names efficiently. Moreover, we make comparative analysis of lookup behavior between wired and wireless users. Secondly, with messages received or send by DNS servers we can find these DNS servers' behaviors, i.e., TTLs, equivalent answers and are able to accurately identify domain names with dynamic IP addresses. We provide different and specific visualization techniques for presenting these analysis results and show these techniques are very useful for understanding user behaviors, analyzing security events and characterizing overall tendency in campus network management. (C) 2015 Published by Elsevier B.V.
机译:域名系统(DNS)是一项重要的Internet服务,它可以将容易记住的域名转换为数字IP地址,以查找计算机资源和服务。在本文中,我们尝试通过从中国大型大学校园网络中的三台主要DNS服务器提取DNS日志来探索DNS查找的行为。我们的数据集由两部分组成,即DNS查询日志和DNS服务器接收或发送的消息。首先,通过分析这些DNS查询日志,我们可以了解用户浏览的总体趋势。为了处理庞大的DNS数据集,我们引入了一种称为DNSReduce的算法,该算法可用于有效地挖掘出前10个客户端IP地址和前10个目标域名。此外,我们对有线和无线用户之间的查找行为进行了比较分析。其次,利用DNS服务器接收或发送的消息,我们可以找到这些DNS服务器的行为,即TTL,等效答案,并能够准确地标识具有动态IP地址的域名。我们提供了不同而具体的可视化技术来呈现这些分析结果,并表明这些技术对于了解用户行为,分析安全事件以及表征校园网络管理的总体趋势非常有用。 (C)2015由Elsevier B.V.发布

著录项

  • 来源
    《Neurocomputing》 |2015年第2期|100-109|共10页
  • 作者单位

    Peking Univ, Sch Elect Engn & Comp Sci, Beijing 100871, Peoples R China;

    Peking Univ, Ctr Comp, Beijing 100871, Peoples R China;

    Peking Univ, Ctr Comp, Beijing 100871, Peoples R China;

    Peking Univ, Ctr Comp, Beijing 100871, Peoples R China;

    Peking Univ, Sch Elect Engn & Comp Sci, Beijing 100871, Peoples R China;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    DNS lookup; Visualization; User behavior;

    机译:DNS查找;可视化;用户行为;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号