• DocumentCode
    2264969
  • Title

    SDBF: Smart DNS brute-forcer

  • Author

    Wagner, Cynthia ; François, Jérôme ; State, Radu ; Engel, Thomas ; Wagener, Gerard ; Dulaunoy, Alexandre

  • Author_Institution
    SnT - Interdiscipl. Centre for Security Reliability & Trust, Univ. of Luxembourg, Luxembourg, Luxembourg
  • fYear
    2012
  • fDate
    16-20 April 2012
  • Firstpage
    1001
  • Lastpage
    1007
  • Abstract
    The structure of the domain name is highly relevant for providing insights into the management, organization and operation of a given enterprise. Security assessment and network penetration testing are using information sourced from the DNS service in order to map the network, perform reconnaissance tasks, identify services and target individual hosts. Tracking the domain names used by popular Botnets is another major application that needs to undercover their underlying DNS structure. Current approaches for this purpose are limited to simplistic brute force scanning or reverse DNS, but these are unreliable. Brute force attacks depend of a huge list of known words and thus, will not work against unknown names, while reverse DNS is not always setup or properly configured. In this paper, we address the issue of fast and efficient generation of DNS names and describe practical experiences against real world large scale DNS names. Our approach is based on techniques derived from natural language modeling and leverage Markov Chain Models in order to build the first DNS scanner (SDBF) that is leveraging both, training and advanced language modeling approaches.
  • Keywords
    Internet; Markov processes; natural language processing; program testing; security of data; DNS scanner; DNS service; Markov chain models; SDBF; botnets; brute force attacks; brute force scanning; domain name structure; domain name system; natural language modeling; network penetration testing; reconnaissance tasks; reverse DNS; security assessment; smart DNS brute-forcer; Dictionaries; Feature extraction; Generators; Markov processes; Measurement; Probes; Servers;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network Operations and Management Symposium (NOMS), 2012 IEEE
  • Conference_Location
    Maui, HI
  • ISSN
    1542-1201
  • Print_ISBN
    978-1-4673-0267-8
  • Electronic_ISBN
    1542-1201
  • Type

    conf

  • DOI
    10.1109/NOMS.2012.6212021
  • Filename
    6212021