Araştırma Makalesi

Identification of abnormal DNS traffic with Hurst parameter

Cilt: 6 Sayı: 3 31 Temmuz 2018
PDF İndir
EN

Identification of abnormal DNS traffic with Hurst parameter

Öz

It is a necessity for effective network management to be aware of the activities taking place on computer networks. Network managers should always be alarmed about what is happening now, what might be, or what will be in the future for the sake of network. To gather information about a computer system or a network, attackers mostly exploit networking tools to gain some privileges and login systems. Penetration testers also use these tools to gather information about systems, but their main concern is to discover the vulnerabilities of the system, and to find out what kind of measures could be applied to make the system more resistant to these vulnerabilities. In this study, we propose an abnormal DNS traffic identification method via utilizing Hurst parameter estimation. To do so, we employ DNS information gathering tools in Kali Linux to generate abnormal DNS flows. Then, we estimate its self-similarity degree to compare the differences between normal DNS traffic flows and abnormal ones. Obtained results show that abnormal DNS traffic show higher self-similarity degrees. Another interesting finding is that abnormal DNS traffic shows different distribution characteristic.

Anahtar Kelimeler

Kaynakça

  1. [1] H. Chen, J.H. Cho, and S. Hu, “Quantifying the Security Effectiveness of Firewalls and DMZs”, In Proceedings of the 5th Annual Symposium and Bootcamp on Hot Topics in the Science of Security, ACM, 2018.
  2. [2] A. Patel, M. Taghavi, K. Bakhtiyari, and J. Celestino JúNior. "An intrusion detection and prevention system in cloud computing: A systematic review", Journal of network and computer applications, vol. 36, no. 1 , 2013, pp- 25-41.
  3. [3] U.A. Sandhu, S. Haider, S. Naseer, and O. U. Ateeb, “A survey of intrusion detection & Prevention Techniques”, 2011 International Conference on Information Communication and Managenent IPCSIT, vol. 16, Singapore, 2011, pp. 66-67.
  4. [4] M. Wielorgorshka, and D. O’Brien, DNS Traffic Analysis for Botnet Detection.
  5. [5] C. Hyunsang, H. Lee, H. Lee, and H. Kim. "Botnet detection by monitoring group activities in DNS traffic", In Computer and Information Technology, 2007. CIT 2007. 7th IEEE International Conference on, 2007, pp. 715-720.
  6. [6] C. Hyunsang, and H. Lee. "Identifying botnets by capturing group activities in DNS traffic", Computer Networks, vol. 56, no. 1, 2012, pp. 20-33.
  7. [7] M.A. Hussain, H. Jin, Z.A. Hussien, Z.A. Abduljabbar, S.H. Abbdal, A. İbrahim, “DNS Protection Against Spoofing and Poisoning Attacks”, 3rd International Conference on Information Science and Control Engineering (ICISCE), Beijing China, 2016, pp. 1308-1312.
  8. [8] M. Anagnostopoulos, G. Kambourakis, P. Kopanos, G. Louloudakis, and S. Gritzalis. "DNS amplification attack revisited." Computers & Security 39, 2013, pp. 475-485.

Ayrıntılar

Birincil Dil

İngilizce

Konular

Mühendislik

Bölüm

Araştırma Makalesi

Yayımlanma Tarihi

31 Temmuz 2018

Gönderilme Tarihi

21 Haziran 2018

Kabul Tarihi

25 Temmuz 2018

Yayımlandığı Sayı

Yıl 2018 Cilt: 6 Sayı: 3

Kaynak Göster

APA
Gezer, A. (2018). Identification of abnormal DNS traffic with Hurst parameter. Balkan Journal of Electrical and Computer Engineering, 6(3), 191-197. https://doi.org/10.17694/bajece.435230
AMA
1.Gezer A. Identification of abnormal DNS traffic with Hurst parameter. Balkan Journal of Electrical and Computer Engineering. 2018;6(3):191-197. doi:10.17694/bajece.435230
Chicago
Gezer, Ali. 2018. “Identification of abnormal DNS traffic with Hurst parameter”. Balkan Journal of Electrical and Computer Engineering 6 (3): 191-97. https://doi.org/10.17694/bajece.435230.
EndNote
Gezer A (01 Temmuz 2018) Identification of abnormal DNS traffic with Hurst parameter. Balkan Journal of Electrical and Computer Engineering 6 3 191–197.
IEEE
[1]A. Gezer, “Identification of abnormal DNS traffic with Hurst parameter”, Balkan Journal of Electrical and Computer Engineering, c. 6, sy 3, ss. 191–197, Tem. 2018, doi: 10.17694/bajece.435230.
ISNAD
Gezer, Ali. “Identification of abnormal DNS traffic with Hurst parameter”. Balkan Journal of Electrical and Computer Engineering 6/3 (01 Temmuz 2018): 191-197. https://doi.org/10.17694/bajece.435230.
JAMA
1.Gezer A. Identification of abnormal DNS traffic with Hurst parameter. Balkan Journal of Electrical and Computer Engineering. 2018;6:191–197.
MLA
Gezer, Ali. “Identification of abnormal DNS traffic with Hurst parameter”. Balkan Journal of Electrical and Computer Engineering, c. 6, sy 3, Temmuz 2018, ss. 191-7, doi:10.17694/bajece.435230.
Vancouver
1.Ali Gezer. Identification of abnormal DNS traffic with Hurst parameter. Balkan Journal of Electrical and Computer Engineering. 01 Temmuz 2018;6(3):191-7. doi:10.17694/bajece.435230

Cited By

All articles published by BAJECE are licensed under the Creative Commons Attribution 4.0 International License. This permits anyone to copy, redistribute, remix, transmit and adapt the work provided the original work and source is appropriately cited.Creative Commons Lisans