学位论文详细信息
Improving internet security via large-scale passive and active dns monitoring
Anomaly detection;DNS monitoring;Internet security
Antonakakis, Emmanouil Konstantinos ; Computing
University:Georgia Institute of Technology
Department:Computing
关键词: Anomaly detection;    DNS monitoring;    Internet security;   
Others  :  https://smartech.gatech.edu/bitstream/1853/44780/1/antonakakis_emmanouil_k_201208_phd.pdf
美国|英语
来源: SMARTech Repository
PDF
【 摘 要 】

The Domain Name System (DNS) is a critical component of the Internet. DNS provides the ability to map human-readable and memorable domain names to machine-level IP addresses and other records. These mappings lie at the heart of the Internet's success and are essential for the majority of core Internet applications and protocols.The critical nature of DNS means that it is often the target of abuse. Cyber-criminals rely heavily upon the reliability and scalability of the DNS protocol to serve as an agile platform for their illicit operations. For example, modern malware and Internet fraud techniques rely upon DNS to locate their remote command-and-control (C&C) servers through which new commands from the attacker are issued, serve as exfiltration points for information stolen from the victims' computers, and to manage subsequent updates to their malicious toolset.The research described in this thesis scientifically addresses problems in the area of DNS-based detection of illicit operations. In detail, this research studies new methods to quantify and track dynamically changing reputations for DNS based on passive network measurements. The research also investigates methods for the creation of early warning systems for DNS. These early warning systems enables the research community to identify emerging threats (e.g., new botnets and malware infections) across the DNS hierarchy in a timelier manner.

【 预 览 】
附件列表
Files Size Format View
Improving internet security via large-scale passive and active dns monitoring 7243KB PDF download
  文献评价指标  
  下载次数:7次 浏览次数:12次