Detection of NS Resource Record DNS Resolution Traffic, Host Search, and SSH Dictionary Attack Activities
スポンサーリンク
概要
- 論文の詳細を見る
We performed an entropy study on the DNS query traffic from the Internet to the top domain DNS server in a university campus network through January 1st to March 31st, 2009. The obtained results are: (1) We observed a difference for the entropy changes among the total-, the A-, and the PTR resource records (RRs) based DNS query traffic from the Internet through January 17th to February 1st, 2009. (2) We found the large NS RR based DNS query traffic including only a keyword "." in the total DNS query traffic from the Internet. (3) We also found that the unique source IP address based PTR DNS traffic entropy slightly increased, while the unique DNS query keywords based one drastically decreased in March 9th, 2009. We found a specific IP host which was an already-hijacked classical Linux PC that carried out the SSH dictionary attack to the Internet sites in March 9th, 2009. From these results, we can detect the unusual NS RR based DNS traffic and SSH dictionary attacks by only watching DNS query traffic from the Internet.
- 2009-05-21
著者
-
Yasuo Musashi
Center for Multimedia and Information Technologies (CMIT), Kumamoto University
-
Shinichiro Kubota
Center for Multimedia and Information Technologies (CMIT), Kumamoto University
-
Kenichi Sugitani
Center for Multimedia and Information Technologies (CMIT), Kumamoto University
-
Yasuo Musashi
Center For Multimedia And Information Technologies Kumamoto University
-
Kazuya Takemori
Graduate School Of Science And Technology Kumamoto University
-
Shinichiro Kubota
Center For Multimedia And Information Technologies Kumamoto University
-
Kenichi Sugitani
Center For Multimedia And Information Technologies Kumamoto University
-
Yasuo Musashi
Center For Multimedia And Information Technologies (cmit) Kumamoto University
-
Shinichiro Kubota
Center For Multimedia And Information Technologies (cmit) Kumamoto University
関連論文
- Detection of Host Search Attacks in PTR Resource Record DNS Query Packet Traffic
- Detection of Host Name Harvesting Attack in PTR Resource Record Based DNS Query Packet Traffic
- Detection of NS Resource Record DNS Resolution Traffic, Host Search, and SSH Dictionary Attack Activities
- Detection of SSH Dictionary Attack in DNS Reverse Resolution Traffic