DNSSM: A Large Scale Passive DNS Security Monitoring Framework - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2012

DNSSM: A Large Scale Passive DNS Security Monitoring Framework

Résumé

We present a monitoring approach and the supporting software architecture for passive DNS traffic. Monitoring DNS traffic can reveal essential network and system level activity profiles. Worm infected and botnet participating hosts can be identified and malicious backdoor communications can be detected. Any passive DNS monitoring solution needs to address several challenges that range from architectural approaches for dealing with large volumes of data up to specific Data Mining approaches for this purpose. We describe a framework that leverages state of the art distributed processing facilities with clustering techniques in order to detect anomalies in both online and offline DNS traffic. This framework entitled DNSSM is implemented and operational on several networks. We validate the framework against two large trace sets.
Fichier principal
Vignette du fichier
dnssm.pdf (947.4 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-00749243 , version 1 (07-11-2012)

Identifiants

Citer

Samuel Marchal, Jérôme François, Cynthia Wagner, Radu State, Alexandre Dulaunoy, et al.. DNSSM: A Large Scale Passive DNS Security Monitoring Framework. Network Operations and Management Symposium, Apr 2012, Lahaina, United States. pp.988 - 993, ⟨10.1109/NOMS.2012.6212019⟩. ⟨hal-00749243⟩
516 Consultations
947 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More