Characterizing DNS Malicious Traffic in Big Data

Wenqi Sun, Songyang Wu, Tao Zhang · 2019

DNS is a quite critical network service while it is a critical attack vector. DNS vulnerabilities and attacks have been studied for many years. However, what parameters are efficient to identify specific type of DNS attacks? This question becomes more important in order to ensure DNS security in this big data era. This paper firstly characterizes main types of DNS attacks, and then gives some analytic methods to detect malicious traffic in big network data. Based on a recent dataset in a competition, analysis is carried out to verify our methods. We try to obtain some hints along with DNS malicious traffic, which might be helpful to carry out quick and efficient attack detection in huge data.

Read the paper · More papers on PaperTik