DocumentCode
2264969
Title
SDBF: Smart DNS brute-forcer
Author
Wagner, Cynthia ; François, Jérôme ; State, Radu ; Engel, Thomas ; Wagener, Gerard ; Dulaunoy, Alexandre
Author_Institution
SnT - Interdiscipl. Centre for Security Reliability & Trust, Univ. of Luxembourg, Luxembourg, Luxembourg
fYear
2012
fDate
16-20 April 2012
Firstpage
1001
Lastpage
1007
Abstract
The structure of the domain name is highly relevant for providing insights into the management, organization and operation of a given enterprise. Security assessment and network penetration testing are using information sourced from the DNS service in order to map the network, perform reconnaissance tasks, identify services and target individual hosts. Tracking the domain names used by popular Botnets is another major application that needs to undercover their underlying DNS structure. Current approaches for this purpose are limited to simplistic brute force scanning or reverse DNS, but these are unreliable. Brute force attacks depend of a huge list of known words and thus, will not work against unknown names, while reverse DNS is not always setup or properly configured. In this paper, we address the issue of fast and efficient generation of DNS names and describe practical experiences against real world large scale DNS names. Our approach is based on techniques derived from natural language modeling and leverage Markov Chain Models in order to build the first DNS scanner (SDBF) that is leveraging both, training and advanced language modeling approaches.
Keywords
Internet; Markov processes; natural language processing; program testing; security of data; DNS scanner; DNS service; Markov chain models; SDBF; botnets; brute force attacks; brute force scanning; domain name structure; domain name system; natural language modeling; network penetration testing; reconnaissance tasks; reverse DNS; security assessment; smart DNS brute-forcer; Dictionaries; Feature extraction; Generators; Markov processes; Measurement; Probes; Servers;
fLanguage
English
Publisher
ieee
Conference_Titel
Network Operations and Management Symposium (NOMS), 2012 IEEE
Conference_Location
Maui, HI
ISSN
1542-1201
Print_ISBN
978-1-4673-0267-8
Electronic_ISBN
1542-1201
Type
conf
DOI
10.1109/NOMS.2012.6212021
Filename
6212021
Link To Document