首页> 外文OA文献 >Automatic detection of DNS manipulations
【2h】

Automatic detection of DNS manipulations

机译:自动检测DNS操纵

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

The DNS is a fundamental service that has been repeatedly attacked and abused. DNS manipulation is a prominent case: Recursive DNS resolvers are deployed to explicitly return manipulated answers to users' queries. While DNS manipulation is used for legitimate reasons too (e.g., parental control), rogue DNS resolvers support malicious activities, such as malware and viruses, exposing users to phishing and content injection. We introduce REMeDy, a system that assists operators to identify the use of rogue DNS resolvers in their networks. REMeDy is a completely automatic and parameter-free system that evaluates the consistency of responses across the resolvers active in the network. It operates by passively analyzing DNS traffic and, as such, requires no active probing of third-party servers. REMeDy is able to detect resolvers that manipulate answers, including resolvers that affect unpopular domains. We validate REMeDy using large-scale DNS traces collected in ISP networks where more than 100 resolvers are regularly used by customers. REMeDy automatically identifies regular resolvers, and pinpoint manipulated responses. Among those, we identify both legitimate services that offer additional protection to clients, and resolvers under the control of malwares that steer traffic with likely malicious goals.
机译:DNS是已经多次攻击和滥用的基本服务。 DNS操作是一个突出的例子:递归DNS解析器部署到明确地返回操纵回答用户的查询。虽然DNS操纵用于正当理由太(例如,父母控制),流氓DNS解析器支持恶意活动,例如恶意软件和病毒,露出用户网络钓鱼和内容注射。我们介绍的补救措施,一家帮助运营商识别在他们的网络中使用流氓DNS解析器的系统。补救措施是完全自动和无参数系统,用于评估的多个活动网络中的旋转变压器的响应的一致性。它的工作由被动地分析DNS流量和,因此,不需要活跃的第三方服务器探测。补救的方法是能够检测操纵答案解析器,包括影响不受欢迎域解析器。我们使用的ISP网络,其中超过100个解析器经常被客户用来收集大型DNS痕迹验证补救措施。补救自动识别正规的解析器,并精确操控响应。在这些,我们确定恶意软件的控制下都合法的服务,提供给客户额外的保护,并且解析器与可能是恶意的目标转向交通。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号