Malicious Traffic Blocking Mechanism and Protection Based on DNS

Ruei-Jan Hung, Chien-Chung Hsu, Jiun-Huei Ho · 2023

We implemented the “Domain Intelligence Joint Defense System (DIPDS)” to detect and block malicious domains. By integrating the information provided by internal and external threat intelligence and corporating DNS query logs, we analyzed and identified abnormal behavior and traffic, and then developed detection and blocking mechanisms for cybersecurity maintenance. By setting domain server query restriction policies, the overall mechanism became more complete, preventing users from evading detection and blocking mechanisms. From August 2022 to February 2023, we deployed the Domain Intelligence Joint Defense System within the company, and zombie computers that cybersecurity maintenance personnel could not discover were blocked. During the period, we found a total of 6 zombie computers, blocked 1,307,088 malicious domain connections, and discovered 25 mining hosts. The research results showed that the Domain Intelligence Joint Defense System (DIPDS) effectively reduced cybersecurity risks and the occurrence of corporate cybersecurity incidents.

Read the paper · More papers on PaperTik