Human- and Machine-Generated Traffic Distinction by DNS Protocol Analysis

Marcin Ochab, Marcin Mrukowicz, Jaromir Sarzyński, Urszula Bentkowska · 2021

In this contribution we analyze a real DNS traffic collected at the University of Rzeszów campus. All DNS queries and responses observed in the entire network were gathered. Data include traffic generated by students, scholars, and other staff members as well as servers, IoT and all other devices connected to network. Data was collected using the Tshark network protocol analyzer and stored in a ClickHouse columnar-oriented database dedicated for high volume data analyses. Fuzzy C-means clustering was applied to analyze DNS traffic and to distinguish between human- and machine generated traffic. Analysis was performed on a representative sample containing 3 516 094 records and 33 proposed features.

Read the paper · More papers on PaperTik