DocumentCode :
2842178
Title :
Detection of NS Resource Record Based DNS Query Request Packet Traffic and SSH Dictionary Attack Activity
Author :
Takemori, Kazuya ; Romaa, D. ; Kubota, Shinichiro ; Sugitani, Kenichi ; Musashi, Yasuo
Author_Institution :
Graduation Sch. of Sci. & Technol., Kumamoto Univ., Kumamoto, Japan
fYear :
2009
fDate :
1-3 Nov. 2009
Firstpage :
246
Lastpage :
249
Abstract :
We carried out an entropy study on the DNS query traffic from the Internet to the top domain DNS server in a university campus network through January 1st to March 31st, 2009. The obtained results are: (1) We observed a difference for the entropy changes among the total-, the A-, and the PTR resource records (RRs) based DNS query traffic from the Internet through January 17th to February 1st, 2009. (2) We found the large NS RR based DNS query traffic including only a keyword "." in the total DNS query traffic from the Internet. (3) We also found that the unique source IP address based PTR DNS traffic entropy slightly increased, while the unique DNS query keywords based one drastically decreased in March 9th, 2009. We found a specific IP host which was an already-hijacked classical Linux PC that carried out the SSH dictionary attack to the Internet sites in March 9th, 2009. From these results, we can detect the unusual NS RR based DNS traffic and SSH dictionary attacks by only watching DNS query traffic from the Internet.
Keywords :
IP networks; Internet; entropy; query processing; telecommunication security; telecommunication traffic; DNS query keyword; DNS query request packet traffic; DNS server; IP address; Internet; NS resource record detection; PTR DNS traffic entropy; PTR resource record; SSH dictionary attack activity; already-hijacked classical Linux PC; university campus network; Computer crime; Dictionaries; Electronic mail; Entropy; IP networks; Intelligent networks; Internet; Network servers; Telecommunication traffic; Web server; DNS based detection; SSH dictionary attack; anomaly detection; bot network; bots;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Intelligent Networks and Intelligent Systems, 2009. ICINIS '09. Second International Conference on
Conference_Location :
Tianjin
Print_ISBN :
978-1-4244-5557-7
Electronic_ISBN :
978-0-7695-3852-5
Type :
conf
DOI :
10.1109/ICINIS.2009.69
Filename :
5364840
Link To Document :
بازگشت