首页> 外文OA文献 >Leveraging client-side DNS failure patterns to identify malicious behaviors
【2h】

Leveraging client-side DNS failure patterns to identify malicious behaviors

机译:利用客户端DNS故障模式来识别恶意行为

摘要

DNS has been increasingly abused by adversaries for cyber-attacks. Recent research has leveraged DNS failures (i.e. DNS queries that result in a Non-Existent-Domain response from the server) to identify malware activities, especially domain-flux botnets that generate many random domains as a rendezvous technique for command-&-control. Using ISP network traces, we conduct a systematic analysis of DNS failure characteristics, with the goal of uncovering how attackers exploit DNS for malicious activities. In addition to DNS failures generated by domain-flux bots, we discover many diverse and stealthy failure patterns that have received little attention. Based on these findings, we present a framework that detects diverse clusters of suspicious domain names that cause DNS failures, by considering multiple types of syntactic as well as temporal patterns. Our evolutionary learning framework evaluates the clusters produced over time to eliminate spurious cases while retaining sustaining (i.e., highly suspicious) clusters. One of the advantages of our framework is in analyzing DNS failures on per-client basis and not hinging on the existence of multiple clients infected by the same malware. Our evaluation on a large ISP network trace shows that our framework detects at least 97% of the clients with suspicious DNS behaviors, with over 81% precision.
机译:DNS已越来越多地被攻击者用于网络攻击。最近的研究利用DNS故障(即导致服务器发出不存在域响应的DNS查询)来识别恶意软件活动,尤其是生成大量随机域作为命令与控制交会技术的域通量僵尸网络。通过使用ISP网络跟踪,我们对DNS失败特征进行了系统分析,目的是发现攻击者如何利用DNS进行恶意活动。除了网域漫游器产生的DNS故障外,我们还发现了许多鲜为人知的多样且隐秘的故障模式。基于这些发现,我们提出了一个框架,该框架通过考虑多种类型的句法和时间模式来检测导致DNS故障的各种可疑域名。我们的进化学习框架会评估随时间推移而产生的集群,以消除伪造案例,同时保留可持续的(即高度可疑)集群。我们框架的优势之一是可以基于每个客户端分析DNS故障,而不必担心存在由同一恶意软件感染的多个客户端。我们对大型ISP网络跟踪的评估表明,我们的框架检测到至少97%的可疑DNS行为客户端,其准确性超过81%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号