DNS query log data enrichment based on cyber threat intelligence
Hilya Q. Najahah, Muhammad A. Salamun, Fadhlan Z. Muttaqin, Nur Rohman Rosyid · AIP conference proceedings · 2023
DNS is an essential part of the internet; therefore, DNS security is a crucial issue that must consider.Performing log data analysis can anticipate DNS attacks.Log itself is a file that contains records of events that happen in a system.So, utilizing log data can help prevent and identify harmful activities that may occur in a system.Cyber threat intelligence provides current threat information; therefore, enriching data using relevant information can make data more proper.This research carried out enrichment mechanisms based on cyber threat intelligence.The system is designed to analyze and process DNS query logs and add some relevant information.This research aims to enrich the DNS query log with a series of information related to correlation events and the reputation of IP, and it can identify possible threats to DNS.