Skip to main navigation Skip to search Skip to main content

The Rapid Extraction of Suspicious Traffic from Passive DNS

  • Beihang University
  • National Internet Emergency Center

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

The network traffic is filled with numerous malicious requests, most of which is generated by amplified attacks, random subdomain name attacks and botnets. Through using DNS traffic for malicious behavior analysis, we often need to test each domain alone. Besides, the amount of data is very large and simple filtering cannot quickly reduce the need to detect the number of domain names. As a result, it takes a lot of time to calculate on the premise of limited resources. Therefore, this paper introduces a extraction scheme for DNS traffic. We designed a simple and efficient method for extracting three kinds of attack traffic with the largest proportion of traffic. Besides, the method of statistics and classification was used to deal with all the traffic. We implemented a prototype system and evaluated it on real-world DNS traffic. In the meanwhile, as the recall rate reached almost 100%, the number of secondary domain names to be detected was reduced to 8% of the original quantity, and the DNS record to be detected was reduced to 1% of the original number.

Original languageEnglish
Title of host publicationICISSP 2018 - Proceedings of the 4th International Conference on Information Systems Security and Privacy
EditorsPaolo Mori, Steven Furnell, Olivier Camp
PublisherSciTePress
Pages190-198
Number of pages9
ISBN (Electronic)9789897582820
DOIs
StatePublished - 2018
Event4th International Conference on Information Systems Security and Privacy, ICISSP 2018 - Funchal, Madeira, Portugal
Duration: 22 Jan 201824 Jan 2018

Publication series

NameICISSP 2018 - Proceedings of the 4th International Conference on Information Systems Security and Privacy
Volume2018-January

Conference

Conference4th International Conference on Information Systems Security and Privacy, ICISSP 2018
Country/TerritoryPortugal
CityFunchal, Madeira
Period22/01/1824/01/18

Keywords

  • Amplification Attack
  • DNS
  • Domain Generation Algorithm
  • Malicious Domain Name
  • Random Subdomain Attack

Fingerprint

Dive into the research topics of 'The Rapid Extraction of Suspicious Traffic from Passive DNS'. Together they form a unique fingerprint.

Cite this