Detection of Host Name Harvesting Attack in PTR Resource Record Based DNS Query Packet Traffic
スポンサーリンク
概要
- 論文の詳細を見る
We statistically investigated the total inbound PTR resource record (RR) based DNS query request packet traffic to the top domain DNS server in a university campus network through January 1st to December 31st, 2009. The obtained results are: (1) We observed fourteen host name harvesting (HnH) attacks that we can observe rapid decreases in the unique source IP address based entropy of the inbound PTR RR based the DNS query packet traffic and significant increases in the unique DNS query keyword based one. (2) We found the consecutive and random IP addresses in the PTR RR based DNS query request packet traffic through the days of January 8th and 21st, 2009, respectively. Also (3), we calculated Euclidian distances between the observed IP address and the last observed IP address as the DNS query keywords and we detected two kinds of HnH attacks by a range of thresholds for 1.0-2.0 and 150.2-210.4. Therefore, these results show that we can detect more easily the inbound HnH attacks by calculating the Euclidian distances among the observed IP addresses in the inbound PTR RR based DNS query request packet traffic.
- 2010-05-06
著者
-
Yasuo Musashi
Center for Multimedia and Information Technologies (CMIT), Kumamoto University
-
DennisArturoLudeñaRomaña
Graduate School of Science and Technology, Kumamoto University
-
Shinichiro Kubota
Center for Multimedia and Information Technologies (CMIT), Kumamoto University
-
Kenichi Sugitani
Center for Multimedia and Information Technologies (CMIT), Kumamoto University
-
Yasuo Musashi
Center For Multimedia And Information Technologies Kumamoto University
-
Shinichiro Kubota
Center For Multimedia And Information Technologies Kumamoto University
-
Kenichi Sugitani
Center For Multimedia And Information Technologies Kumamoto University
-
Yasuo Musashi
Center For Multimedia And Information Technologies (cmit) Kumamoto University
-
Shinichiro Kubota
Center For Multimedia And Information Technologies (cmit) Kumamoto University
関連論文
- Detection of Host Search Attacks in PTR Resource Record DNS Query Packet Traffic
- Detection of Host Name Harvesting Attack in PTR Resource Record Based DNS Query Packet Traffic
- Detection of NS Resource Record DNS Resolution Traffic, Host Search, and SSH Dictionary Attack Activities
- Detection of SSH Dictionary Attack in DNS Reverse Resolution Traffic