Fast and Accurate Identification of Active Recursive Domain Name Servers in High-speed Network
Title | Fast and Accurate Identification of Active Recursive Domain Name Servers in High-speed Network |
Publication Type | Conference Paper |
Year of Publication | 2016 |
Authors | Liu, Xiaomei, Sun, Yong, Huang, Caiyun, Zou, Xueqiang, Qin, Zhiguang |
Conference Name | Proceedings of the 2016 ACM International on Workshop on Traffic Measurements for Cybersecurity |
Publisher | ACM |
Conference Location | New York, NY, USA |
ISBN Number | 978-1-4503-4284-1 |
Keywords | connectivity estimation, evaluate security risk degrees, Human Behavior, pubcrawl, recursive nameservers |
Abstract | Fast and accurate identification of active recursive domain name servers (RDNS) is a fundamental step to evaluate security risk degrees of DNS systems. Much identification work have been proposed based on network traffic measurement technology. Even though identifying RDNS accurately, they waste huge network resources, and fail to obtain host activity and distinguish between direct and indirect RDNS. In this paper, we proposed an approach to identify direct and forward RDNS based on our three key insights on their request-response behaviors, and proposed an approach to identify indirect RDNS based on CNAME redirect behaviors. To work in high-speed backbone networks, we further proposed an online connectivity estimation algorithm to obtain estimated values used in our identification approaches. According to our experiments, we can identify RDNS with a high accuracy by selecting the reasonable thresholds. The accuracy of identifying direct and forward RDNS can reach 89%.The accuracy of identifying indirect RDNS can reach 90%.Moreover, our work is capable of real-time analyzing high speed backbone traffics. |
URL | http://doi.acm.org/10.1145/2903185.2903190 |
DOI | 10.1145/2903185.2903190 |
Citation Key | liu_fast_2016 |