DocumentCode :
2264969
Title :
SDBF: Smart DNS brute-forcer
Author :
Wagner, Cynthia ; François, Jérôme ; State, Radu ; Engel, Thomas ; Wagener, Gerard ; Dulaunoy, Alexandre
Author_Institution :
SnT - Interdiscipl. Centre for Security Reliability & Trust, Univ. of Luxembourg, Luxembourg, Luxembourg
fYear :
2012
fDate :
16-20 April 2012
Firstpage :
1001
Lastpage :
1007
Abstract :
The structure of the domain name is highly relevant for providing insights into the management, organization and operation of a given enterprise. Security assessment and network penetration testing are using information sourced from the DNS service in order to map the network, perform reconnaissance tasks, identify services and target individual hosts. Tracking the domain names used by popular Botnets is another major application that needs to undercover their underlying DNS structure. Current approaches for this purpose are limited to simplistic brute force scanning or reverse DNS, but these are unreliable. Brute force attacks depend of a huge list of known words and thus, will not work against unknown names, while reverse DNS is not always setup or properly configured. In this paper, we address the issue of fast and efficient generation of DNS names and describe practical experiences against real world large scale DNS names. Our approach is based on techniques derived from natural language modeling and leverage Markov Chain Models in order to build the first DNS scanner (SDBF) that is leveraging both, training and advanced language modeling approaches.
Keywords :
Internet; Markov processes; natural language processing; program testing; security of data; DNS scanner; DNS service; Markov chain models; SDBF; botnets; brute force attacks; brute force scanning; domain name structure; domain name system; natural language modeling; network penetration testing; reconnaissance tasks; reverse DNS; security assessment; smart DNS brute-forcer; Dictionaries; Feature extraction; Generators; Markov processes; Measurement; Probes; Servers;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Network Operations and Management Symposium (NOMS), 2012 IEEE
Conference_Location :
Maui, HI
ISSN :
1542-1201
Print_ISBN :
978-1-4673-0267-8
Electronic_ISBN :
1542-1201
Type :
conf
DOI :
10.1109/NOMS.2012.6212021
Filename :
6212021
Link To Document :
بازگشت