DocumentCode
659497
Title
A fast and scalable method for threat detection in large-scale DNS logs
Author
Begleiter, Ron ; Elovici, Yuval ; Hollander, Yona ; Mendelson, Ori ; Rokach, L. ; Saltzman, Roi
Author_Institution
Fortscale Inc., Tel-Aviv, Israel
fYear
2013
fDate
6-9 Oct. 2013
Firstpage
738
Lastpage
741
Abstract
This paper presents a fast and scalable method for detecting threats in large-scale DNS logs. In such logs, queries about “abnormal” domain strings are often correlated with malicious behavior. With our method, a language model algorithm learns “normal” domain-names from a large dataset to rate the extent of domain-name “abnormality” within a big data stream of DNS queries in the organization. Variable-order Markov Models (VMMs) serve as out underlying algorithmic tool since their running time is linear in the input sequence while their memory requirements are constantly bounded from above, both very appealing characteristics. Our experimental study indicates that the proposed method can detect domain names generated by a genuine Domain Generation Algorithm, used in Advanced Persistent Threat attack scenarios, with less than 5% false-negative and 1% false-positive rates. This detection rate is similar to more computationally intensive methods that are not scalable for big data environments.
Keywords
Internet; Markov processes; invasive software; query processing; DNS queries; VMM; abnormal domain strings; advanced persistent threat attack scenarios; algorithmic tool; big data stream; detection rate; domain generation algorithm; domain name detection; domain-name abnormality; false-negative rate; false-positive rate; input sequence; language model algorithm; large-scale DNS Logs; linear running time; malicious behavior; memory requirements; normal domain-names; threat detection; variable-order Markov models; Context; Data handling; Information management; Malware; Prediction algorithms; Training;
fLanguage
English
Publisher
ieee
Conference_Titel
Big Data, 2013 IEEE International Conference on
Conference_Location
Silicon Valley, CA
Type
conf
DOI
10.1109/BigData.2013.6691646
Filename
6691646
Link To Document