Paper Abstract and Keywords |
Presentation |
2015-03-06 10:50
Analysis of direct outbound queries in DNS and consideration of malicious traffic detection method Hikaru Ichise, Yong Jin, Katsuyoshi Iida (Tokyo Inst. of Tech) SITE2014-74 IA2014-106 |
Abstract |
(in Japanese) |
(See Japanese page) |
(in English) |
Direct outbound DNS queries from inside PCs to outside computers without any authority information are not considered as normal behaviors in DNS protocol and one of the possible reasons of such queries is that the inside PCs are infected by some kind of bot program in which the IP addresses of the unknown outside computers are hard-coded. Thus it is possible to effectively detect botnet communications by catching such abnormal direct outbound DNS queries. In this paper, we discuss the possibility of detecting botnet communications as well as malicious traffics by analyzing the direct outbound DNS queries that are not using the DNS resolvers of the organizations. |
Keyword |
(in Japanese) |
(See Japanese page) |
(in English) |
Botnet / Direct outbound query / DNS / Malicious traffic / / / / |
Reference Info. |
IEICE Tech. Rep., vol. 114, no. 495, IA2014-106, pp. 173-178, March 2015. |
Paper # |
IA2014-106 |
Date of Issue |
2015-02-26 (SITE, IA) |
ISSN |
Print edition: ISSN 0913-5685 Online edition: ISSN 2432-6380 |
Copyright and reproduction |
All rights are reserved and no part of this publication may be reproduced or transmitted in any form or by any means, electronic or mechanical, including photocopy, recording, or any information storage and retrieval system, without permission in writing from the publisher. Notwithstanding, instructors are permitted to photocopy isolated articles for noncommercial classroom use without fee. (License No.: 10GA0019/12GB0052/13GB0056/17GB0034/18GB0034) |
Download PDF |
SITE2014-74 IA2014-106 |
Conference Information |
Committee |
IA IPSJ-IOT SITE |
Conference Date |
2015-03-05 - 2015-03-06 |
Place (in Japanese) |
(See Japanese page) |
Place (in English) |
|
Topics (in Japanese) |
(See Japanese page) |
Topics (in English) |
Internet and Information Ethics Education, etc. |
Paper Information |
Registration To |
IA |
Conference Code |
2015-03-IA-IOT-SITE |
Language |
Japanese |
Title (in Japanese) |
(See Japanese page) |
Sub Title (in Japanese) |
(See Japanese page) |
Title (in English) |
Analysis of direct outbound queries in DNS and consideration of malicious traffic detection method |
Sub Title (in English) |
|
Keyword(1) |
Botnet |
Keyword(2) |
Direct outbound query |
Keyword(3) |
DNS |
Keyword(4) |
Malicious traffic |
Keyword(5) |
|
Keyword(6) |
|
Keyword(7) |
|
Keyword(8) |
|
1st Author's Name |
Hikaru Ichise |
1st Author's Affiliation |
Tokyo Institute Of Technology (Tokyo Inst. of Tech) |
2nd Author's Name |
Yong Jin |
2nd Author's Affiliation |
Tokyo Institute Of Technology (Tokyo Inst. of Tech) |
3rd Author's Name |
Katsuyoshi Iida |
3rd Author's Affiliation |
Tokyo Institute Of Technology (Tokyo Inst. of Tech) |
4th Author's Name |
|
4th Author's Affiliation |
() |
5th Author's Name |
|
5th Author's Affiliation |
() |
6th Author's Name |
|
6th Author's Affiliation |
() |
7th Author's Name |
|
7th Author's Affiliation |
() |
8th Author's Name |
|
8th Author's Affiliation |
() |
9th Author's Name |
|
9th Author's Affiliation |
() |
10th Author's Name |
|
10th Author's Affiliation |
() |
11th Author's Name |
|
11th Author's Affiliation |
() |
12th Author's Name |
|
12th Author's Affiliation |
() |
13th Author's Name |
|
13th Author's Affiliation |
() |
14th Author's Name |
|
14th Author's Affiliation |
() |
15th Author's Name |
|
15th Author's Affiliation |
() |
16th Author's Name |
|
16th Author's Affiliation |
() |
17th Author's Name |
|
17th Author's Affiliation |
() |
18th Author's Name |
|
18th Author's Affiliation |
() |
19th Author's Name |
|
19th Author's Affiliation |
() |
20th Author's Name |
|
20th Author's Affiliation |
() |
Speaker |
Author-1 |
Date Time |
2015-03-06 10:50:00 |
Presentation Time |
25 minutes |
Registration for |
IA |
Paper # |
SITE2014-74, IA2014-106 |
Volume (vol) |
vol.114 |
Number (no) |
no.494(SITE), no.495(IA) |
Page |
pp.173-178 |
#Pages |
6 |
Date of Issue |
2015-02-26 (SITE, IA) |
|