Multi-dimensional Aggregation for DNS Monitoring - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2013

Multi-dimensional Aggregation for DNS Monitoring

Résumé

DNS is an essential service in the Internet as it allows to translate human language based domain names into IP addresses. DNS traffic reflects the user activities and behaviors. It is thus a helpful source of information in the context of large scale network monitoring. In particular, passive DNS monitoring garnered much interest for the security perspectives by highlighting the services the machines want to access. In this paper, we propose a new method for assessing the dynamics of the match between DNS names and IP subnetworks using an efficient aggregating scheme combined with relevant steadiness metrics. The evaluation relies on real data collected over several months and is able to detect anomalies related to malicious domains.
Fichier principal
Vignette du fichier
Multi-dimensional_Aggregation_for_DNS_Monitoring.pdf (1.02 Mo) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-00959430 , version 1 (14-03-2014)

Identifiants

Citer

Lautaro Dolberg, Jérôme François, Thomas Engel. Multi-dimensional Aggregation for DNS Monitoring. Local Computer Networks, Oct 2013, Sydney, Australia. pp.390 - 398, ⟨10.1109/LCN.2013.6761271⟩. ⟨hal-00959430⟩
73 Consultations
287 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More