DETECTION AND MITIGATION OF MALICIOUS ACTIVITIES BASED ON DNS QUERY ANALYSIS
Georgi Markov, Borislav Nikolov · Environment Technology Resources Proceedings of the International Scientific and Practical Conference · 2025
With the increasing number of cyber threats and the growing complexity of attacks on network infrastructures, the need for effective methods to detect malicious activities has become critically important. One of the key attack vectors is the Domain Name System (DNS), which plays a fundamental role in internet communication. Although DNS is essential for every end user, it often remains unnoticed and unprotected, making it vulnerable to abuses such as DDoS attacks, attack surface reconnaissance, and data exfiltration. The aim of this study is to develop a method for automated analysis of DNS traffic to enable early detection of suspicious patterns and prevent potential attacks. To achieve this, open-source tools, publicly available databases, and log files from a real authoritative DNS server are utilized. The methodology includes analysing the frequency and type of DNS queries, as well as evaluating the IP addresses from which they originate. The results of the analysis demonstrate that automated processing of DNS logs allows for the identification of anomalous query patterns associated with malicious activities. Systematic monitoring of DNS traffic provides an opportunity for early threat detection and faster implementation of protective measures. The proposed approach enhances cybersecurity mechanisms by strengthening threat intelligence capabilities and automating the detection process. This underscores the significance of the research and the necessity of continuously improving protection methods in the dynamic landscape of cybersecurity.