1 Detection of DNS Anomalies using Flow Data Analysis

Anestis Karasaridis, Kathleen S. Meier-Hellstern, David Hoeflin · 2013

Abstract — The Domain Name System (DNS) is an essential network infrastructure component since it supports the operation of the Web, Email, Voice over IP (VoIP) and other businesscritical applications running over the network. Events that compromise the security of DNS can have a significant impact on the Internet since they can affect its availability and its intended operation. This paper describes algorithms used to monitor and detect certain types of attacks to the DNS infrastructure using flow data. Our methodology is based on algorithms that do not rely on known signature attack vectors. The effectiveness of our solution is illustrated with real and simulated traffic examples. In one example, we were able to detect a tunneling attack well before the appearence of public reports of it.

Read the paper · More papers on PaperTik