- Book Chapter
- 10.1016/b978-155860746-0/50042-9
34 - Sending Data to a Server
- Jan 01, 2004
- Interactive QuickTime
- Matthew Peterson
34 - Sending Data to a Server
Associating network traffic with human-readable domain names, instead of low-level identifiers like IP addresses, is helpful for measuring traffic by domain name, rate-limiting packets by domain, and identifying IoT devices. However, existing monitoring techniques require examining traffic at an external compute node, introducing overhead and privacy risks. In this paper, we introduce Meta4, a framework for monitoring traffic by domain name in the data plane by extracting the client IP, server IP, and domain name from DNS response messages and associating the domain name with data traffic from the subsequent client-server session. A data-plane implementation has the benefits of running efficiently at line-rate, enabling the switch to take direct action on the packets (e.g., to rate-limit, block, or mark traffic based on the associated domain), and protecting the privacy of user information. We implemented Meta4 on an Intel Tofino switch and evaluated our prototype against packet traces from an operational network.
34 - Sending Data to a Server
34 - Sending Data to a Server
Visualizing and characterizing DNS lookup behaviors via log-mining
Visualizing and characterizing DNS lookup behaviors via log-mining
An Abnormal Domain Name Generation Method Based on a Character-Level Model
Internet technology develops by leaps and bounds, new types of botnet attacks are springing up. Currently, most malware are stealthy when implementing attacks since they can bypass detection strategies such as blacklists and sinkholes. These malware mainly use DGA to generate many random domain names to prevent C&C server IP addresses from being traced to the source. To resist botnet attacks, machine-learning methods have been proposed for detecting abnormal domain names. However, there are still some inadequacies, e.g., detection methods based on manual feature extraction couldn't identify novel variant DGA domains, and existing neural network detection methods have weak generalization ability and lack training data for new variant DGA domain names. To address the above problems, this paper proposes an abnormal domain name data generation technology based on a character-level model. Firstly, combining specific text generation-related ideas improves the character-level language model. Secondly, the Bi-GRU network model and attention mechanism are used to thoroughly learn the internal correlation features, and simulate the generation of abnormal domain names. The experimental results show that this method's abnormal domain name data is highly similar to the actual domain name in relative entropy and character composition. Furthermore, it verifies the feasibility of the generated data as training data set for a new variant DGA domain name, which to a certain extent, helps to improve the generalization ability of the abnormal domain name detection model.
Read moreCHAPTER 8 - Installing, Configuring as a Server
CHAPTER 8 - Installing, Configuring as a Server
The Quest for Information Privacy in Africa: A Review Essay
The Quest for Information Privacy in Africa: A Review Essay
Blockchain-Based Sealed-Bid Domain Name Auction Protocol
Domain name system (DNS), mapping domain names to IP addresses, is critical to the Internet’s running. However, the centralized architecture is one of the major criticisms of the current DNS. Many works suggest introducing the blockchain into DNS, but the existing blockchain-based DNSs do not support the domain name auction that is important for the domain name transfer. To solve this problem, we in this paper propose a blockchain-based sealed-bid domain name auction protocol by combining the smart contract, the Pedersen commitment, and zero-knowledge proof. Compared with the previous blockchain-based auction protocols, our proposal is the first one holding the tx-fairness, bidding-fairness, bid-guarantee, and fund-privacy at the same time. For showing its effectiveness, we also give an illustration of our proposal based on the smart contract system in Ethereum.
Read moreHeavy-Hitter Detection Entirely in the Data Plane
Identifying the "heavy hitter" flows or flows with large traffic volumes in the data plane is important for several applications e.g., flow-size aware routing, DoS detection, and traffic engineering. However, measurement in the data plane is constrained by the need for line-rate processing (at 10-100Gb/s) and limited memory in switching hardware. We propose HashPipe, a heavy hitter detection algorithm using emerging programmable data planes. HashPipe implements a pipeline of hash tables which retain counters for heavy flows while evicting lighter flows over time. We prototype HashPipe in P4 and evaluate it with packet traces from an ISP backbone link and a data center. On the ISP trace (which contains over 400,000 flows), we find that HashPipe identifies 95% of the 300 heaviest flows with less than 80KB of memory.
Read moreNeural reputation models learned from passive DNS data
Blacklists and whitelists are often employed to filter outgoing and incoming traffic on computer networks. One central function of these lists is to mitigate the security risks posed by malware threats by associating a reputation (for instance benign or malicious) to end-point hosts. The creation and maintenance of these lists is a complex and time-consuming process for security experts. As a consequence, blacklists and whitelists are prone to various errors, inconsistencies and omissions, as only a tiny fraction of end-point hosts are effectively covered by the reputation lists. In this paper, we present a machine learning model that is able to automatically detect whether domain names and IP addresses are benign, malicious or sinkholes. The model relies on a deep neural architecture and is trained on a large passive DNS database. Evaluation results demonstrate the effectiveness of the approach, as the model is able to detect malicious DNS records with a F 1 score of 0.96. In other words, the model is able to detect 95 % of the malicious hosts with a false positive rate of 1:1000.
Read moreILNP: mobility, multi-homing, localised addressing and security through naming
Internet users seek solutions for mobility, multi-homing, support for localised address management (i.e. via NATs), and end-to-end security. Existing mobility approaches are not well integrated into the rest of the Internet architecture, instead primarily being separate extensions that at present are not widely deployed. Because the current approaches to these issues were developed separately, such approaches often are not harmonious when used together. Meanwhile, the Internet has a number of namespaces, for example the IP address or the Domain Name. In recent years, some have postulated that the Internet's namespaces are not sufficiently rich and that the current concept of an address is too limiting. One proposal, the concept of separating an address into an Identifier and a separate Locator, has been controversial in the Internet community for years. It has been considered within the IETF and IRTF several times, but always was rejected as unworkable. This paper takes the position that evolving the naming in the Internet by splitting the address into separate Identifier and Locator names can provide an elegant integrated solution to the key issues listed above, without changing the core routing architecture, while offering incremental deployability through backwards compatibility with IPv6.
Read moreResearch on the algorithm for identifying VoIP session
In this letter, a novel algorithm is proposed for identification of one popular type of VoIP (Voice over IP) application, MSN VoIP, based on both behavior pattern and protocol characteristics. In addition, the experiment for validation is implemented. Since there exists no method identifying MSN VoIP session and furthermore the IP addresses, domain names, ports and even the protocols MSNP works over, are all alterable during the application, which makes it difficult to identify MSN VoIP session, this work will be helpful to advance the research on VoIP identification.
Read morePicP-MUD: Profiling Information Content of Payloads in MUD Flows for IoT Devices
The Manufacturer Usage Description (MUD) standard aims to reduce the attack surface for IoT devices by locking down their behavior to a formally-specified set of network flows (access control entries). Formal network behaviors can also be systematically and rigorously verified in any operating environment. Enforcing MUD flows and monitoring their activity in real-time can be relatively effective in securing IoT devices; however, its scope is limited to endpoints (domain names and IP addresses) and transport-layer protocols and services. Therefore, misconfigured or compromised IoTs may conform to their MUD-specified behavior but exchange unintended (or even malicious) contents across those flows. This paper develops PicP-MUD with the aim to profile the information content of packet payloads (whether unencrypted, encoded, or encrypted) in each MUD flow of an IoT device. That way, certain tasks like cyber-risk analysis, change detection, or selective deep packet inspection can be performed in a more systematic manner. Our contributions are twofold: (1) We analyze over 123K network flows of 6 transparent (e.g., HTTP), 11 encrypted (e.g., TLS), and 7 encoded (e.g., RTP) protocols, collected in our lab and obtained from public datasets, to identify 17 statistical features of their application payload, helping us distinguish different content types; and (2) We develop and evaluate PicP-MUD using a machine learning model, and show how we achieve an average accuracy of 99% in predicting the content type of a flow.
Read moreA Survey on DNS Security Issues and Mitigation Techniques
The Domain Name System (DNS) is the backbone of the internet. It is a distributed hierarchical database which stores resource records like A, MX, AAAA, CNAME. The whole DNS is classified into three layers - root, top-level domain (TLD) and authoritative DNS servers. Each level has its own responsibility to resolve certain categories of domain names. It is very difficult for us to memorize the IP address of each site which we need to visit. In this case, the DNS comes into rescue to figure out the corresponding IP address a domain points to. In the current world, the internet is an inevitable part of our life and DNS is the soul of the internet. Due to this reason, DNS is a major attack target like amplification attack, cache poisoning attack, DNS hijacking, NXDomain attack and Phantom domain attack. These attacks could create a serious security threat to internet users. Threats can be a simple redirection to potentially stealing user credentials. Even though different mitigation techniques are available, the threat still exists. In this paper, we present our survey of the existing research and its shortcomings on securing the DNS. We have also introduced a novel idea which uses blockchain technology to validate the response sent by the DNS servers.
Read moreBlacklist Ecosystem Analysis
Motivation: We compare the contents of 86 Internet blacklists to provide a view of the whole ecosystem of blocking network touch points and blacklists. We aim to formalize and evaluate practitioner tacit knowledge of the fatigue of playing whack-a-mole against resilient adversary resources. Method: Lists are compared to lists of the same data type (domain name or IP address). Different phases of the study use different comparisons. Comparisons include how many lists an indicator is unique to; list sizes; expanded list characterization and intersection; pairwise intersections of all lists; and following, a statistical test we define to determine if one list adds elements shortly after another. Results: Based on a synthesis of multiple methods, domain-name-based indicators are unique to one list 96.16% to 97.37% of the time. IP-address-based indicators are unique to one list 82.46% to 95.24% of the time. Discussion: There is little overlap between blacklists. Though there are exceptions, the intersection between lists remains low even after expanding each list to a larger neighborhood of related indicators. Few lists consistently provide content before other lists if there is intersection. These results suggest that each blacklist describes a distinct sort of malicious activity and that even merging all lists there is no global ground truth to acquire. Practical insights include (1) network defenders are advised to obtain and evaluate as many lists as practical, (2) whack-a-mole is inevitable due to list dynamics, barring a strategic change, an (3) academics comparing their results to one or a few blacklists to test accuracy are advised to reconsider this validation technique.
Read moreEvaluating Web Protocol Threats: DNS Spoofing & TLS Weaknesses
In today's world, browsing the web is one of the everyday activities of our lives. This increasing use of the web by the large number of people puts a heavy burden on the security community to ensure web users are safe and secure. Web traffic today is protected by encryption, and the current technology being used is Transport Layer Security (TLS), which is the upgraded and newer version of previously used Secure Socket Layer (SSL). Additionally, mapping of web domain names to actual addresses on the internet (IP Addresses) is done using Domain Name Service (DNS) protocol. In this paper, we highlight the vulnerabilities of two fundamental protocols of the modern web and internet by developing a Proof of Concept (PoC) tool that exploits these weaknesses when the protocols are misconfigured, potentially compromising a user's web activity. Then, we explain how to avoid these vulnerabilities from the users' perspective, as well as steps web administrators should take to eliminate these flaws. Finally, we perform an empirical study on the top 1k, 10k, and 100k websites and show a large number of them don't make use of HSTS (HTTPS Strict Transport Security) security mechanism, which can secure their users against the same kind of attacks we showcase in this paper. Our goal is to improve the security posture of web users and servers by bringing awareness.
Read moreA Comprehensive Review of DNS-based Distributed Reflection Denial of Service (DRDoS) Attacks: State-of-the-Art
Cyberattacks significantly impact the services based on the internet that is used in our daily lives. Any disruption will make it extremely difficult for us to carry out our daily activities. Cyberattacks will disrupt online services, exploit vulnerabilities to breach databases and servers, and so on. Various systems and services contribute to the Internet’s seamless functionality. The Domain Name System (DNS) is one of the most important services. DNS is used to resolve domain names into machine-readable IP addresses. DNS, like many other Internet services, is vulnerable to cyber-attacks. While DNS faces a slew of threats, one in particular appears to stand out. DNS is vulnerable to a variety of distributed denial-of-service attacks. The distributed reflection denial of service (DRDoS) attack, a flooding attack against DNS servers that renders them unavailable, disrupting domain name resolution activities, is one of the most common variants. DRDoS attacks have been on the rise in recent years. DNS lookup outages would significantly impact our online activities in the world of ultra-connectivity because they are typically the first step in establishing a connection with a server. The purpose of this paper is to present a state-of-the-art review of DRDoS attack detection and mitigation algorithms as well as the datasets on which these algorithms operate. Finally, we discussed each of these algorithms' relative merits and demerits.
Read more