跳到主要导航 跳到搜索 跳到主要内容

The Rapid Extraction of Suspicious Traffic from Passive DNS

  • Beihang University
  • National Internet Emergency Center

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

The network traffic is filled with numerous malicious requests, most of which is generated by amplified attacks, random subdomain name attacks and botnets. Through using DNS traffic for malicious behavior analysis, we often need to test each domain alone. Besides, the amount of data is very large and simple filtering cannot quickly reduce the need to detect the number of domain names. As a result, it takes a lot of time to calculate on the premise of limited resources. Therefore, this paper introduces a extraction scheme for DNS traffic. We designed a simple and efficient method for extracting three kinds of attack traffic with the largest proportion of traffic. Besides, the method of statistics and classification was used to deal with all the traffic. We implemented a prototype system and evaluated it on real-world DNS traffic. In the meanwhile, as the recall rate reached almost 100%, the number of secondary domain names to be detected was reduced to 8% of the original quantity, and the DNS record to be detected was reduced to 1% of the original number.

源语言英语
主期刊名ICISSP 2018 - Proceedings of the 4th International Conference on Information Systems Security and Privacy
编辑Paolo Mori, Steven Furnell, Olivier Camp
出版商SciTePress
190-198
页数9
ISBN(电子版)9789897582820
DOI
出版状态已出版 - 2018
活动4th International Conference on Information Systems Security and Privacy, ICISSP 2018 - Funchal, Madeira, 葡萄牙
期限: 22 1月 201824 1月 2018

出版系列

姓名ICISSP 2018 - Proceedings of the 4th International Conference on Information Systems Security and Privacy
2018-January

会议

会议4th International Conference on Information Systems Security and Privacy, ICISSP 2018
国家/地区葡萄牙
Funchal, Madeira
时期22/01/1824/01/18

指纹

探究 'The Rapid Extraction of Suspicious Traffic from Passive DNS' 的科研主题。它们共同构成独一无二的指纹。

引用此