ENTRADA: enabling DNS big data applications

Maarten Wullink, Moritz Müller, Marco Davids, Giovane C. M. Moura, Cristian Hesselman · 2016

DNS operators, TLD registries, hosting providers, and other Internet operators are frequently faced with the same question: how to draw insights and knowledge from their respective network traffic data in order to improve their services, security, and operations? "Big data" processing solutions play a major role as an enabling platform in this sense, especially with the increasing growth of the volume of Internet traffic. With this in mind, we have developed and presented in a previous work ENTRADA, an open-source high-performance Hadoop-based data streaming warehouse designed to both ingest continuous streams of data and deliver interactive response times over large datasets, even in a small cluster. Whereas in the previous study we focused on the architecture and performance evaluation, in this paper we present a series of use cases and applications that cover phishing, botnets, email security, and visualizations. These applications can be directly used by DNS operators, TLD registries, and researchers to quickly analyze their network data and improve their services, security, and operations.

Read the paper · More papers on PaperTik