- Conference Article
5
- 10.1109/aina.2009.132
Similarity Search over DNS Query Streams for Email Worm Detection
- May 01, 2009
- Nikolaos Chatzis + 1 more +1
S.588-595
A deep dive into DNS behavior and query failures
Similarity Search over DNS Query Streams for Email Worm Detection
S.588-595
Bringing DNS Service to 5G Edge for Reduced Latencies in mMTC Applications
5G brings many improvements to cellular networks in terms of performance, such as lower latency, improved network efficiency, and higher throughput, making it an attractive candidate for many applications. One such domain is industrial applications that may require real-time guarantees to transmit time-critical control messages. Assuming the immense number of devices exchanging data in support of Massive Machine-Type Communications (mMTC) applications, the capability of the cellular infrastructure to handle a large number of real-time transmissions may be inadequate. For such cases, there exists an acute desire to reduce any overheads as much as possible in order to guarantee certain deadlines. One such target is the Domain Name System (DNS) service, for which queries precede almost every new network request. This incorporates additional communication delays based on the response time, which in turn is affected by the proximity of the DNS server. While bringing DNS service to the edge has been touted as a logical solution, its integration with 5G systems is still challenging. This is due to the inability to access the DNS query information at the application layer since the User Equipment (UE) traffic is tunneled through to the core network. To this end, we propose a novel approach that can identify DNS queries at the base stations through Software-Defined Networking (SDN) capabilities. Specifically, we develop an SDN controller which is used to identify and extract DNS queries at the base station and handle the query at the edge without going through the 5G core network. This approach was implemented in a virtualized 5G network, in which we demonstrate that it is feasible and can potentially bring significant performance gains, especially in the case of mMTC applications.
Read moreEmail worm detection by wavelet analysis of DNS query streams
The high prevalence of email worms indicates that current in-network defence mechanisms are incapable of mitigating this Internet threat. Moreover, commonly applied approaches against this class of propagating malicious program do not target reducing unwanted email traffic traversing the Internet. In this paper, we take a step toward better understanding of email worms, and explore their effect on the flow-level characteristics of domain name system (DNS) query streams that user machines generate. We propose a novel method, which uses time series analysis and unsupervised learning, to detect email worms as they appear on local name servers. To evaluate our detection method, we have constructed a DNS query dataset that consists of 71 email worms. We demonstrate that our method is very effective.
Read moreCan We Learn what People are Doing from Raw DNS Queries?
Domain Name System (DNS) is one of the pillars of today's Internet. Due to its appealing properties such as low data volume, wide-ranging applications and encryption free, DNS traffic has been extensively utilized for network monitoring. Most existing studies of DNS traffic, however, focus on domain name reputation. Little attention has been paid to understanding and profiling what people are doing from DNS traffic, a fundamental problem in the areas including Internet demographics and network behavior analysis. Consequently, simple questions like “How to determine whether a DNS query for www.google.com means searching or any other behaviors?” cannot be answered by existing studies. In this paper, we take the first step to identify user activities from raw DNS queries. We advance a multiscale hierarchical framework to tackle two practical challenges, i.e., behavior ambiguity and behavior polymorphism. Under this framework, a series of novel methods, such as pattern upward mapping and multi-scale random forest classifier, are proposed to characterize and identify user activities of interest. Evaluation using both synthetic and real-world DNS traces demonstrates the effectiveness of our method.
Read moreTowards Comprehensive Detection of DNS Tunnels
The Domain Name System (DNS) is a fundamental service of the Internet, and the DNS tunnel is one of the most threatening abuses of DNS, posing a huge threat to user privacy and Internet security. Attackers conceal the information into DNS packets to evade firewalls and intrusion detection systems. Recently, newly developed DNS tunnels used by Advanced Persist Threat groups tend to use A and AAAA resource records (RRs) for transmission, making them more invisible and more threatening. Previous DNS tunnel detection approaches mainly focus on subdomains and TXT RRs, but less attention has been paid to newly developed DNS tunnels based on A and AAAA RRs. In this paper, we present a novel DNS tunnel detection method that can detect newly developed A and AAAA RR based DNS tunnels. Since DNS tunnels will transmit a large amount of encrypted or encoded data in the DNS queries and responses, we extracted novel features from domains and 4 types of RRs (A, AAAA, TXT and CNAME RRs) that are most commonly used for tunneling to measure the amount and content of information exchanged between the authoritative nameservers and the clients. We also analyze the detection capabilities when different features were used. The anomaly detection algorithm is employed on domains related features and 4 types of RRs related features, respectively. The overlaps of outliers will be marked as DNS tunnels. Our approach has been evaluated on real-world network traffic. The experimental results show that our approach can detect all DNS tunnels in the dataset with a extremely low false positive rate.
Read moreAnalysis of Privacy Disclosure in DNS Query
When a DNS (domain name system) client needs to look up a name, it queries DNS servers to resolve the name on the Internet. The query information from the client was passed through one or more DNS servers. While useful, in the whole query transmission, we say it can leak potentially sensitive information: what a client wants to connect to, or what the client is always paying attention to. From the definition, the privacy problem is to prove that none of the private data can be inferred from the information which is made public. We first analyzed the complete DNS query process now in use; then, from each step of the DNS query process, we discussed the privacy disclosure problem in each step of the query: client side, query transmission process and DNS server side. Finally, we proposed a simple and flexible privacy-preserving query scheme "range query", which could maximally decrease privacy disclosure in the whole DNS query process. And we also discuss efficiency and implementation on the range query.
Read moreVisualizing and characterizing DNS lookup behaviors via log-mining
Visualizing and characterizing DNS lookup behaviors via log-mining
A Survey on Malicious Domains Detection through DNS Data Analysis
Malicious domains are one of the major resources required for adversaries to run attacks over the Internet. Due to the important role of the Domain Name System (DNS), extensive research has been conducted to identify malicious domains based on their unique behavior reflected in different phases of the life cycle of DNS queries and responses. Existing approaches differ significantly in terms of intuitions, data analysis methods as well as evaluation methodologies. This warrants a thorough systematization of the approaches and a careful review of the advantages and limitations of every group. In this article, we perform such an analysis. To achieve this goal, we present the necessary background knowledge on DNS and malicious activities leveraging DNS. We describe a general framework of malicious domain detection techniques using DNS data. Applying this framework, we categorize existing approaches using several orthogonal viewpoints, namely (1) sources of DNS data and their enrichment, (2) data analysis methods, and (3) evaluation strategies and metrics. In each aspect, we discuss the important challenges that the research community should address in order to fully realize the power of DNS data analysis to fight against attacks leveraging malicious domains.
Read moreAddressing the challenges of modern DNS a comprehensive tutorial
The Domain Name System (DNS) plays a crucial role in connecting services and users on the Internet. Since its first specification, DNS has been extended in numerous documents to keep it fit for today’s challenges and demands. And these challenges are many. Revelations of snooping on DNS traffic led to changes to guarantee confidentiality of DNS queries. Attacks to forge DNS traffic led to changes to shore up the integrity of the DNS. Finally, denial-of-service attack on DNS operations have led to new DNS operations architectures. All of these developments make DNS a highly interesting, but also highly challenging research topic. This tutorial – aimed at graduate students and early-career researchers – provides a overview of the modern DNS, its ongoing development and its open challenges. This tutorial has four major contributions. We first provide a comprehensive overview of the DNS protocol. Then, we explain how DNS is deployed in practice. This lays the foundation for the third contribution: a review of the biggest challenges the modern DNS faces today and how they can be addressed. These challenges are (i) protecting the confidentiality and (ii) guaranteeing the integrity of the information provided in the DNS, (iii) ensuring the availability of the DNS infrastructure, and (iv) detecting and preventing attacks that make use of the DNS. Last, we discuss which challenges remain open, pointing the reader towards new research areas.
Read moreLocal and Public DNS Resolvers: do you trade off performance against security?
The Domain Name System (DNS) is a vital component of the Internet, used for all the operations performed over the network and, recently, also for protecting users from malicious activities. In this work, we analyze the behavior of DNS resolvers provided by three main Italian ISPs and contrast them with open, public resolvers provided by Google and Cisco. We consider two aspects. The first one is the time spent to perform a query and obtain a response from the resolvers, which has a considerable impact on the performance of most applications on the Internet. The second one is the capability to recognize domains associated with malicious activities, blocking related requests to protect users. The DNS response time is generally shorter for local resolvers since they are closer to the users. On the other hand, public resolvers are typically considered more efficient in detecting malicious domains. We performed a large number of DNS queries towards the different resolvers, both local and public, using different sets of domain names and different Internet access networks from main Italian providers. Our results confirm that the response time of local resolvers is shorter than the public ones. However, they also show that, unexpectedly, the protection level of local resolvers is largely comparable with the one of public resolvers. Consequently, you do not have to trade off security against performance. In addition, we study the impact of DNS over HTTPs, we unveil the different mechanisms implemented to block users from accessing malicious domains and assess the impact of caching on the obtained results.
Read moreDEEPAV2: A DNS monitor tool for prevention of public IP DNS rebinding attack
Domain Name Systems (DNS) play a vital role in the proper functioning of the internet Almost all internet applications rely on DNS for the name resolutions. The existing DNS infrastructure has a number of security vulnerabilities and it is prone to attacks such as DNS Cache Poisoning attack, DNS Rebinding attack. Flooding attack, etc. If a DNS server is compromised, it affects all the users of the internet, resulting in adverse effect In this paper the focus has been on the prevention of DNS Rebinding attack. The solution for detecting and preventing DNS rebinding attack has been incorporated into DEEP A1. The extended DEEPA, viz., DEEPAV2 tool, containing the enhanced packet analyzer, the traffic differentiator, and enhanced packet filter modules, detects and differentiates the abnormal group of activities in the DNS traffic caused by the public IP DNS rebinding attack which is the combination of classical DNS rebinding attack and Anti-DNS pinning attack. The DEEPAV2 effectively filters the DNS rebinding attack packets by deeply analyzing the DNS packets. As the DNS rebinding attack is prevented, the subsequent attacks such as pharming, phishing, click frauds, email spamming, etc., could be prevented.
Read moreA Survey on DNS Security Issues and Mitigation Techniques
The Domain Name System (DNS) is the backbone of the internet. It is a distributed hierarchical database which stores resource records like A, MX, AAAA, CNAME. The whole DNS is classified into three layers - root, top-level domain (TLD) and authoritative DNS servers. Each level has its own responsibility to resolve certain categories of domain names. It is very difficult for us to memorize the IP address of each site which we need to visit. In this case, the DNS comes into rescue to figure out the corresponding IP address a domain points to. In the current world, the internet is an inevitable part of our life and DNS is the soul of the internet. Due to this reason, DNS is a major attack target like amplification attack, cache poisoning attack, DNS hijacking, NXDomain attack and Phantom domain attack. These attacks could create a serious security threat to internet users. Threats can be a simple redirection to potentially stealing user credentials. Even though different mitigation techniques are available, the threat still exists. In this paper, we present our survey of the existing research and its shortcomings on securing the DNS. We have also introduced a novel idea which uses blockchain technology to validate the response sent by the DNS servers.
Read moreA Comprehensive Review of DNS-based Distributed Reflection Denial of Service (DRDoS) Attacks: State-of-the-Art
Cyberattacks significantly impact the services based on the internet that is used in our daily lives. Any disruption will make it extremely difficult for us to carry out our daily activities. Cyberattacks will disrupt online services, exploit vulnerabilities to breach databases and servers, and so on. Various systems and services contribute to the Internet’s seamless functionality. The Domain Name System (DNS) is one of the most important services. DNS is used to resolve domain names into machine-readable IP addresses. DNS, like many other Internet services, is vulnerable to cyber-attacks. While DNS faces a slew of threats, one in particular appears to stand out. DNS is vulnerable to a variety of distributed denial-of-service attacks. The distributed reflection denial of service (DRDoS) attack, a flooding attack against DNS servers that renders them unavailable, disrupting domain name resolution activities, is one of the most common variants. DRDoS attacks have been on the rise in recent years. DNS lookup outages would significantly impact our online activities in the world of ultra-connectivity because they are typically the first step in establishing a connection with a server. The purpose of this paper is to present a state-of-the-art review of DRDoS attack detection and mitigation algorithms as well as the datasets on which these algorithms operate. Finally, we discussed each of these algorithms' relative merits and demerits.
Read moreCache Function Activation on a Client Based DNSSEC Validation and Alert System by Multithreading
Domain Name System (DNS) is one of the most important services of the Internet since most communications normally begin with domain name resolutions provided by DNS. However, DNS has vulnerability against some kind of attacks such as DNS spoofing, DNS cache poisoning, and so on. DNSSEC is an security extension of DNS to provide secure name resolution services by using digital signature based on public key cryptography. However, there are several problems with DNSSEC such as failing resolution in case of validation failure, increasing the load of DNS full resolver, and so on. To mitigate these problems, we proposed a Client Based DNSSEC Validation System. This system performs DNSSEC validation on the client, and in case of validation failure, it forwards the failed response and alerts the user to the fact. However, this system has a problem that it inactivates the cache function of validation library so that it always performs DNSSEC validation even for the same query. In this paper, we report how to solve this problem by multithreading of DNSSEC validation system.
Read more결함내성을 가진 도메인네임 서버의 구축 및 연동시험
DNS(Domain Name System)는 인터넷상의 호스트의 도메인주소를 IP주소로 변환하거나 IP주소를 도메인주소로 변환하는 이름해결 메카니즘을 총칭한다. 본 논문에서는 1차 DNS 서버가 오류로 인해 정지하더라도 2차 DNS 서버가 대신하여 서비스를 지속할 수 있도록 하는 결함내성을 갖는 DNS 시스템 구축에 관해 연구하였다. DNS(Domain Name System) is the Name Resolution Mechanism that makes conversion from a Domain Name of a computer on the Internet to an IP Address or the reverse conversion. In this paper we researched on the Foundation techniques of Fault-tolerant DNS Servers that the secondary DNS can take over and provide continuous services even though primary DNS stops due to some critical errors.
Read more