講演抄録/キーワード |
講演名 |
2009-03-05 14:20
Entropy Study on A Resource Record DNS Query Traffic from the Campus Network Kazuya Takemori・○Wei Juan Kong・Dennis Arturo Ludena Romana・Shinichiro Kubota・Kenichi Sugitani・Yasuo Musashi(Kumamoto Univ.) SITE2008-61 IA2008-84 |
抄録 |
(和) |
We investigated the source IP address (SIP)- and query keyword (QK)-based entropy changes in the A and PTR resource records (RRs) based DNS query traffic between the DNS clients and the campus DNS server through January 1st to December 31st, 2008. The results are: (1) The both entropies simultaneously decrease when the targeted attack activity is high. (2) The SIP-based entropy increases while the QK-based one decreases, simultaneously, when the random attack activity is high. (3) The SIP-based entropy decreases while the QK-based one increases, at the same time, when the host search activity is high. Therefore, we can get important information for the security incidents by only observing the DNS query traffic. |
(英) |
We investigated the source IP address (SIP)- and query keyword (QK)-based entropy changes in the A and PTR resource records (RRs) based DNS query traffic between the DNS clients and the campus DNS server through January 1st to December 31st, 2008. The results are: (1) The both entropies simultaneously decrease when the targeted attack activity is high. (2) The SIP-based entropy increases while the QK-based one decreases, simultaneously, when the random attack activity is high. (3) The SIP-based entropy decreases while the QK-based one increases, at the same time, when the host search activity is high. Therefore, we can get important information for the security incidents by only observing the DNS query traffic. |
キーワード |
(和) |
DNS based detection / DNS traffic entropy / spam bot / host search / / / / |
(英) |
DNS based detection / DNS traffic entropy / spam bot / host search / / / / |
文献情報 |
信学技報, vol. 108, no. 460, IA2008-84, pp. 101-106, 2009年3月. |
資料番号 |
IA2008-84 |
発行日 |
2009-02-26 (SITE, IA) |
ISSN |
Print edition: ISSN 0913-5685 Online edition: ISSN 2432-6380 |
著作権に ついて |
技術研究報告に掲載された論文の著作権は電子情報通信学会に帰属します.(許諾番号:10GA0019/12GB0052/13GB0056/17GB0034/18GB0034) |
PDFダウンロード |
SITE2008-61 IA2008-84 |
|