• DocumentCode
    3449263
  • Title

    DNS ANY Request Cannon Activity in DNS Query Packet Traffic

  • Author

    Takeda, Y. ; Musashi, Yasuo ; Sugitani, Kenichi ; Moriyama, Takumi

  • Author_Institution
    Grad. Sch. of Sci. & Technol., Kumamoto Univ., Kumamoto, Japan
  • fYear
    2013
  • fDate
    1-3 Nov. 2013
  • Firstpage
    181
  • Lastpage
    184
  • Abstract
    We statistically investigated the total ANY resource record (RR) based DNS query request packet traffic from the Internet to the top domain DNS server in a university campus network through January 1st, 2011 to December 31st, 2012. The obtained results are: (1) We found a significant increase in the inbound ANY RR based DNS query request traffic at November 28th, 2011. (2) In the DNS query request packet traffic, we observed only a query keyword of the campus domain name. (3) We found a correlation between the total inbound DNS query request packet traffic and the DNS query request packet traffic including the query keyword. (4) Also, we carried out the loading test sending ANY, A, and PTR RR unique DNS queries to a test DNS server, we observed no difference among the vmstat parameters, and the load value was 0.10-0.20. These results indicate that the ANY RR based DNS request packet traffic is quite strange. However, it should be meaningless activity.
  • Keywords
    Internet; computer network security; query processing; telecommunication traffic; ANY RR based DNS query request traffic; ANY resource record; DNS ANY request cannon activity; DNS query packet traffic; Internet; PTR RR; campus domain name; domain DNS server; inbound DNS query request packet traffic; query keyword; university campus network; vmstat parameters; Computer crime; Educational institutions; IP networks; Intelligent networks; Internet; Loading; Servers; DNS ANY Request Cannon; DNS Log Analysis; DoS attack;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Intelligent Networks and Intelligent Systems (ICINIS), 2013 6th International Conference on
  • Conference_Location
    Shenyang
  • Print_ISBN
    978-1-4799-2808-8
  • Type

    conf

  • DOI
    10.1109/ICINIS.2013.53
  • Filename
    6754702