Threat Identification Using Active DNS Measurements

Olivier van der Toorn*, Anna Sperotto

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionAcademicpeer-review

62 Downloads (Pure)

Abstract

The DNS is a core service for the Internet. Most uses of the DNS are benign, but some are malicious. Attackers often use a DNS domain to enable an attack (e.g. DDoS attacks). Detection of these attacks often happens passively, which leads to a reactive detection of attacks. However, registering and configuring a domain takes time. We want to pro-actively identify malicious domains during this time. Identifying malicious domains before they are used allows to pre-emptively stop an attack. We aim to accomplish this goal by analysing active DNS measurements. Through the analysis of active DNS measurements there is a window of opportunity between the time of registration and the time of an attack to identify a threat before it becomes an attack. Active DNS measurements allows us to analyse the configuration of a domain. Using the configuration of a domain we can predict if it will be used for malicious intent. Machine Learning (ML) is often used to process large datasets, because it is efficient and dynamic. This is the reason we want to use ML for the detection of malicious domains. Because our results are predictive in nature, methodology for validation of our results need to be developed. At the time of the detection ground truth is not (yet) available.

Original languageEnglish
Title of host publication12th International Conference on Autonomous Infrastructure, Management and Security, AIMS 2018 - Proceedings
PublisherIFIP
Pages1-5
Number of pages5
ISBN (Electronic)978-3-903176-12-6
Publication statusPublished - 2018
Event12th International Conference on Autonomous Infrastructure, Management and Security, AIMS 2018 - Munich, Germany
Duration: 4 Jun 20187 Jun 2018
Conference number: 12
http://www.aims-conference.org/2018/

Conference

Conference12th International Conference on Autonomous Infrastructure, Management and Security, AIMS 2018
Abbreviated titleAIMS 2018
Country/TerritoryGermany
CityMunich
Period4/06/187/06/18
Internet address

Fingerprint

Dive into the research topics of 'Threat Identification Using Active DNS Measurements'. Together they form a unique fingerprint.

Cite this