Title :
SDBF: Smart DNS brute-forcer
Author :
Wagner, Cynthia ; François, Jérôme ; State, Radu ; Engel, Thomas ; Wagener, Gerard ; Dulaunoy, Alexandre
Author_Institution :
SnT - Interdiscipl. Centre for Security Reliability & Trust, Univ. of Luxembourg, Luxembourg, Luxembourg
Abstract :
The structure of the domain name is highly relevant for providing insights into the management, organization and operation of a given enterprise. Security assessment and network penetration testing are using information sourced from the DNS service in order to map the network, perform reconnaissance tasks, identify services and target individual hosts. Tracking the domain names used by popular Botnets is another major application that needs to undercover their underlying DNS structure. Current approaches for this purpose are limited to simplistic brute force scanning or reverse DNS, but these are unreliable. Brute force attacks depend of a huge list of known words and thus, will not work against unknown names, while reverse DNS is not always setup or properly configured. In this paper, we address the issue of fast and efficient generation of DNS names and describe practical experiences against real world large scale DNS names. Our approach is based on techniques derived from natural language modeling and leverage Markov Chain Models in order to build the first DNS scanner (SDBF) that is leveraging both, training and advanced language modeling approaches.
Keywords :
Internet; Markov processes; natural language processing; program testing; security of data; DNS scanner; DNS service; Markov chain models; SDBF; botnets; brute force attacks; brute force scanning; domain name structure; domain name system; natural language modeling; network penetration testing; reconnaissance tasks; reverse DNS; security assessment; smart DNS brute-forcer; Dictionaries; Feature extraction; Generators; Markov processes; Measurement; Probes; Servers;
Conference_Titel :
Network Operations and Management Symposium (NOMS), 2012 IEEE
Conference_Location :
Maui, HI
Print_ISBN :
978-1-4673-0267-8
Electronic_ISBN :
1542-1201
DOI :
10.1109/NOMS.2012.6212021