A Client Based Anomaly Traffic Detection and Blocking Mechanism by Monitoring DNS Name Resolution with User Alerting Feature
Yong Jin, Kunitaka Kakoi, Nariyoshi Yamai, Naoya Kitagawa, Masahiko Tomoishi · 2018
Malware has become one of the most critical targets of network security solutions nowadays. Many types of malware receive further instructions from the C&C servers and the attack targets may be instructed by IP addresses which causes direct attacks without DNS name resolution from the malware-infected computers. In the meanwhile, several programs that are hidden from the users (e.g. malware, virus, etc.) may perform DNS name resolutions for cyber attacks or other communications. In this paper, we propose a client based anomaly traffic detection and blocking mechanism by monitoring DNS name resolution per application program. In the proposed mechanism, by the collaboration of DNS proxy and packet filter, DNS traffic is monitored on the client and the traffic destined to the IP addresses obtained without DNS name resolution or the traffic from unrecognized programs will be detected and blocked. In addition, in order to mitigate false positive detection, an alert-window will be shown to let the users decide whether to allow the traffic or not. We implemented a prototype system on a Windows 7 client and confirmed that the proposed mechanism worked as expected.