- Research Article
13
- 10.1016/j.neucom.2014.09.099
Visualizing and characterizing DNS lookup behaviors via log-mining
- May 16, 2015
- Neurocomputing
- Qingnan Lai + 4 more +4
Visualizing and characterizing DNS lookup behaviors via log-mining
Internet users seek solutions for mobility, multi-homing, support for localised address management (i.e. via NATs), and end-to-end security. Existing mobility approaches are not well integrated into the rest of the Internet architecture, instead primarily being separate extensions that at present are not widely deployed. Because the current approaches to these issues were developed separately, such approaches often are not harmonious when used together. Meanwhile, the Internet has a number of namespaces, for example the IP address or the Domain Name. In recent years, some have postulated that the Internet's namespaces are not sufficiently rich and that the current concept of an address is too limiting. One proposal, the concept of separating an address into an Identifier and a separate Locator, has been controversial in the Internet community for years. It has been considered within the IETF and IRTF several times, but always was rejected as unworkable. This paper takes the position that evolving the naming in the Internet by splitting the address into separate Identifier and Locator names can provide an elegant integrated solution to the key issues listed above, without changing the core routing architecture, while offering incremental deployability through backwards compatibility with IPv6.
Visualizing and characterizing DNS lookup behaviors via log-mining
Visualizing and characterizing DNS lookup behaviors via log-mining
Analyzing Traffic by Domain Name in the Data Plane
Associating network traffic with human-readable domain names, instead of low-level identifiers like IP addresses, is helpful for measuring traffic by domain name, rate-limiting packets by domain, and identifying IoT devices. However, existing monitoring techniques require examining traffic at an external compute node, introducing overhead and privacy risks. In this paper, we introduce Meta4, a framework for monitoring traffic by domain name in the data plane by extracting the client IP, server IP, and domain name from DNS response messages and associating the domain name with data traffic from the subsequent client-server session. A data-plane implementation has the benefits of running efficiently at line-rate, enabling the switch to take direct action on the packets (e.g., to rate-limit, block, or mark traffic based on the associated domain), and protecting the privacy of user information. We implemented Meta4 on an Intel Tofino switch and evaluated our prototype against packet traces from an operational network.
Read moreCHAPTER 8 - Installing, Configuring as a Server
CHAPTER 8 - Installing, Configuring as a Server
34 - Sending Data to a Server
34 - Sending Data to a Server
Neural reputation models learned from passive DNS data
Blacklists and whitelists are often employed to filter outgoing and incoming traffic on computer networks. One central function of these lists is to mitigate the security risks posed by malware threats by associating a reputation (for instance benign or malicious) to end-point hosts. The creation and maintenance of these lists is a complex and time-consuming process for security experts. As a consequence, blacklists and whitelists are prone to various errors, inconsistencies and omissions, as only a tiny fraction of end-point hosts are effectively covered by the reputation lists. In this paper, we present a machine learning model that is able to automatically detect whether domain names and IP addresses are benign, malicious or sinkholes. The model relies on a deep neural architecture and is trained on a large passive DNS database. Evaluation results demonstrate the effectiveness of the approach, as the model is able to detect malicious DNS records with a F 1 score of 0.96. In other words, the model is able to detect 95 % of the malicious hosts with a false positive rate of 1:1000.
Read moreResearch on the algorithm for identifying VoIP session
In this letter, a novel algorithm is proposed for identification of one popular type of VoIP (Voice over IP) application, MSN VoIP, based on both behavior pattern and protocol characteristics. In addition, the experiment for validation is implemented. Since there exists no method identifying MSN VoIP session and furthermore the IP addresses, domain names, ports and even the protocols MSNP works over, are all alterable during the application, which makes it difficult to identify MSN VoIP session, this work will be helpful to advance the research on VoIP identification.
Read morePicP-MUD: Profiling Information Content of Payloads in MUD Flows for IoT Devices
The Manufacturer Usage Description (MUD) standard aims to reduce the attack surface for IoT devices by locking down their behavior to a formally-specified set of network flows (access control entries). Formal network behaviors can also be systematically and rigorously verified in any operating environment. Enforcing MUD flows and monitoring their activity in real-time can be relatively effective in securing IoT devices; however, its scope is limited to endpoints (domain names and IP addresses) and transport-layer protocols and services. Therefore, misconfigured or compromised IoTs may conform to their MUD-specified behavior but exchange unintended (or even malicious) contents across those flows. This paper develops PicP-MUD with the aim to profile the information content of packet payloads (whether unencrypted, encoded, or encrypted) in each MUD flow of an IoT device. That way, certain tasks like cyber-risk analysis, change detection, or selective deep packet inspection can be performed in a more systematic manner. Our contributions are twofold: (1) We analyze over 123K network flows of 6 transparent (e.g., HTTP), 11 encrypted (e.g., TLS), and 7 encoded (e.g., RTP) protocols, collected in our lab and obtained from public datasets, to identify 17 statistical features of their application payload, helping us distinguish different content types; and (2) We develop and evaluate PicP-MUD using a machine learning model, and show how we achieve an average accuracy of 99% in predicting the content type of a flow.
Read moreA Survey on DNS Security Issues and Mitigation Techniques
The Domain Name System (DNS) is the backbone of the internet. It is a distributed hierarchical database which stores resource records like A, MX, AAAA, CNAME. The whole DNS is classified into three layers - root, top-level domain (TLD) and authoritative DNS servers. Each level has its own responsibility to resolve certain categories of domain names. It is very difficult for us to memorize the IP address of each site which we need to visit. In this case, the DNS comes into rescue to figure out the corresponding IP address a domain points to. In the current world, the internet is an inevitable part of our life and DNS is the soul of the internet. Due to this reason, DNS is a major attack target like amplification attack, cache poisoning attack, DNS hijacking, NXDomain attack and Phantom domain attack. These attacks could create a serious security threat to internet users. Threats can be a simple redirection to potentially stealing user credentials. Even though different mitigation techniques are available, the threat still exists. In this paper, we present our survey of the existing research and its shortcomings on securing the DNS. We have also introduced a novel idea which uses blockchain technology to validate the response sent by the DNS servers.
Read moreBlacklist Ecosystem Analysis
Motivation: We compare the contents of 86 Internet blacklists to provide a view of the whole ecosystem of blocking network touch points and blacklists. We aim to formalize and evaluate practitioner tacit knowledge of the fatigue of playing whack-a-mole against resilient adversary resources. Method: Lists are compared to lists of the same data type (domain name or IP address). Different phases of the study use different comparisons. Comparisons include how many lists an indicator is unique to; list sizes; expanded list characterization and intersection; pairwise intersections of all lists; and following, a statistical test we define to determine if one list adds elements shortly after another. Results: Based on a synthesis of multiple methods, domain-name-based indicators are unique to one list 96.16% to 97.37% of the time. IP-address-based indicators are unique to one list 82.46% to 95.24% of the time. Discussion: There is little overlap between blacklists. Though there are exceptions, the intersection between lists remains low even after expanding each list to a larger neighborhood of related indicators. Few lists consistently provide content before other lists if there is intersection. These results suggest that each blacklist describes a distinct sort of malicious activity and that even merging all lists there is no global ground truth to acquire. Practical insights include (1) network defenders are advised to obtain and evaluate as many lists as practical, (2) whack-a-mole is inevitable due to list dynamics, barring a strategic change, an (3) academics comparing their results to one or a few blacklists to test accuracy are advised to reconsider this validation technique.
Read moreEvaluating Web Protocol Threats: DNS Spoofing & TLS Weaknesses
In today's world, browsing the web is one of the everyday activities of our lives. This increasing use of the web by the large number of people puts a heavy burden on the security community to ensure web users are safe and secure. Web traffic today is protected by encryption, and the current technology being used is Transport Layer Security (TLS), which is the upgraded and newer version of previously used Secure Socket Layer (SSL). Additionally, mapping of web domain names to actual addresses on the internet (IP Addresses) is done using Domain Name Service (DNS) protocol. In this paper, we highlight the vulnerabilities of two fundamental protocols of the modern web and internet by developing a Proof of Concept (PoC) tool that exploits these weaknesses when the protocols are misconfigured, potentially compromising a user's web activity. Then, we explain how to avoid these vulnerabilities from the users' perspective, as well as steps web administrators should take to eliminate these flaws. Finally, we perform an empirical study on the top 1k, 10k, and 100k websites and show a large number of them don't make use of HSTS (HTTPS Strict Transport Security) security mechanism, which can secure their users against the same kind of attacks we showcase in this paper. Our goal is to improve the security posture of web users and servers by bringing awareness.
Read moreCampus Network User Behavior Analysis System Design and Implementation
From the perspective of human science, this paper uses natural science as the tools and methods to analyze student network behavior, considering providing college teaching and student management decision-making as the focal point and fundamental starting point. The utilization of authoritative and professional website Categories ODP, shows the students’ interest in the Internet more accurately. There are many dimensions such as the basic information of students, IP address information of students, the information of college departments, time, the owned domain name, the card information and so on, which analyze the student network behavior in diversified ways. The charts using statistical analysis tools ProClarity to display, combining with the inherent properties of the user, and analyzing the campus network user data, to find the specific modes and laws of the student network user’s behavior and form the valuable knowledge; to find the formation, existing features and changing regularity of the student network users’ behavior, and raise the standards of related resources allocation; to find the features and laws of the student net users’ behavior, analyze the psychological characteristics of students, and provide decision support for student management.
Read moreBlockchain-Based Sealed-Bid Domain Name Auction Protocol
Domain name system (DNS), mapping domain names to IP addresses, is critical to the Internet’s running. However, the centralized architecture is one of the major criticisms of the current DNS. Many works suggest introducing the blockchain into DNS, but the existing blockchain-based DNSs do not support the domain name auction that is important for the domain name transfer. To solve this problem, we in this paper propose a blockchain-based sealed-bid domain name auction protocol by combining the smart contract, the Pedersen commitment, and zero-knowledge proof. Compared with the previous blockchain-based auction protocols, our proposal is the first one holding the tx-fairness, bidding-fairness, bid-guarantee, and fund-privacy at the same time. For showing its effectiveness, we also give an illustration of our proposal based on the smart contract system in Ethereum.
Read moreA Comprehensive Review of DNS-based Distributed Reflection Denial of Service (DRDoS) Attacks: State-of-the-Art
Cyberattacks significantly impact the services based on the internet that is used in our daily lives. Any disruption will make it extremely difficult for us to carry out our daily activities. Cyberattacks will disrupt online services, exploit vulnerabilities to breach databases and servers, and so on. Various systems and services contribute to the Internet’s seamless functionality. The Domain Name System (DNS) is one of the most important services. DNS is used to resolve domain names into machine-readable IP addresses. DNS, like many other Internet services, is vulnerable to cyber-attacks. While DNS faces a slew of threats, one in particular appears to stand out. DNS is vulnerable to a variety of distributed denial-of-service attacks. The distributed reflection denial of service (DRDoS) attack, a flooding attack against DNS servers that renders them unavailable, disrupting domain name resolution activities, is one of the most common variants. DRDoS attacks have been on the rise in recent years. DNS lookup outages would significantly impact our online activities in the world of ultra-connectivity because they are typically the first step in establishing a connection with a server. The purpose of this paper is to present a state-of-the-art review of DRDoS attack detection and mitigation algorithms as well as the datasets on which these algorithms operate. Finally, we discussed each of these algorithms' relative merits and demerits.
Read moreDetecting Algorithmically Generated Domain-Flux Attacks With DNS Traffic Analysis
Recent botnets such as Conficker, Kraken, and Torpig have used DNS-based “domain fluxing” for command-and-control, where each Bot queries for existence of a series of domain names and the owner has to register only one such domain name. In this paper, we develop a methodology to detect such “domain fluxes” in DNS traffic by looking for patterns inherent to domain names that are generated algorithmically, in contrast to those generated by humans. In particular, we look at distribution of alphanumeric characters as well as bigrams in all domains that are mapped to the same set of IP addresses. We present and compare the performance of several distance metrics, including K-L distance, Edit distance, and Jaccard measure. We train by using a good dataset of domains obtained via a crawl of domains mapped to all IPv4 address space and modeling bad datasets based on behaviors seen so far and expected. We also apply our methodology to packet traces collected at a Tier-1 ISP and show we can automatically detect domain fluxing as used by Conficker botnet with minimal false positives, in addition to discovering a new botnet within the ISP trace. We also analyze a campus DNS trace to detect another unknown botnet exhibiting advanced domain-name generation technique.
Read moreTrademarks and Domain Names: Property Rights and Institutional Evolution in Cyberspace
This paper is an empirical study of trademark-based challenges to Internet domain name registrations. It gathered facts about 121 known cases of domain name-trademark conflicts and concludes that domain name registry policies and court decisions had, as of mid-1998, combined to give trademark owners stronger rights over domain names than they had under traditional trademark law. The 121 cases were categorized according to the type of conflict and the kind of settlement or decision that resulted. Types of conflict were broken down into string conflicts, speculation, infringement, and parody. The data show that only about 12% of the cases exhibited the kind of consumer confusion, intent to pass off, or dilution that would normally be considered infringement. In all of the cases of passing off, trademark owners won decisive victories in court. The largest number of domain name-trademark cases (49%) arose from string conflicts, involving common names (such as prince or columbia) that legally may be used concurrently by multiple organizations or businesses. In many of these cases, courts or the NSI registry have allowed trademark owners to take away names from other Internet users. The bias toward trademark owners has been exacerbated by dispute resolution procedures used by domain name registries, which privilege trademark rights over all other claims to the right to use a name. The paper concludes that trademark interests are expanding the scope of their property rights in cyberspace at the expense of smaller Internet users. The paper concludes by proposing changes in law and registry policies that would rectify these injustices.
Read more