Title :
Trends in Host Search Attack in DNS Query Request Packet Traffic
Author :
Shibata, Nobuhiro ; Musashi, Yasuo ; Romana, Dennis Arturo Ludena ; Kubota, Shinichiro ; Sugitani, Kenichi
Author_Institution :
Grad. Sch. of Sci. & Technol., Kumamoto Univ., Kumamoto, Japan
Abstract :
We statistically investigated the total PTR resource record (RR) based DNS query request packet traffic from the Internet to the top domain DNS server in a university campus network through January 1st to December 31st, 2011. The obtained results are: (1) We found twelve host search (HS) attacks in the scores for detection method using the calculated Euclidean distances between the observed IP address and the last observed IP address in the DNS query keywords by employing both threshold ranges of 1.0-2.0 (consecutive) and 150.2-210.4 (random). However, we found nineteen HS attacks in the scores using the calculated cosine distance between the DNS query IP addresses (threshold ranges of 0.75-0.83 and 0.9-1.0). (3) In the newly found HS attacks, we observed that the source IP addresses of the HS attack DNS query packets are distributed. Therefore, it can be concluded that the cosine distance based detection technology has a possibility to detect the source IP address-distributed host search attack.
Keywords :
computer network security; DNS query IP addresses; DNS query keywords; DNS query request packet traffic; Internet; PTR resource record; calculated Euclidean distances; cosine distance based detection technology; detection method; domain DNS server; host search attacks; observed IP address; source IP address-distributed host search attack; university campus network; Computer crime; Detection algorithms; Educational institutions; Euclidean distance; IP networks; Internet; Servers; Advanced Persistent Threats; DNS Host Search Attack; DNS Log Analysis;
Conference_Titel :
Intelligent Networks and Intelligent Systems (ICINIS), 2012 Fifth International Conference on
Conference_Location :
Tianjin
Print_ISBN :
978-1-4673-3083-1
DOI :
10.1109/ICINIS.2012.11