Detection of Fast-Flux Networks Using Various DNS Feature Sets

被引:0
|
作者
Celik, Z. Berkay [1 ]
Oktug, Serna [1 ]
机构
[1] Istanbul Tech Univ, Dept Comp Engn, TR-34469 Istanbul, Turkey
关键词
network security; Fast-flux Service Networks (FFSNs); feature selection; classification;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In this work, we study the detection of Fast-Flux Service Networks (FFSNs) using DNS (Domain Name System) response packets. We have observed that current approaches do not employ a large combination of DNS features to feed into the proposed detection systems. The lack of features may lead to high false positive or false negative rates triggered by benign activities including Content Distribution Networks (CDNs). In this paper, we study recently proposed detection frameworks to construct a high-dimensional feature vector containing timing, network, spatial, domain name, and DNS response information. In the detection system, we strive to use features that are delayfree, and lightweight in terms of storage and computational cost. Feature sub-spaces are evaluated using a C4.5 decision tree classifier by excluding redundant features using the information gain of each feature with respect to each class. Our experiments reveal the performance of each feature subset type in terms of the classification accuracy. Moreover, we present the best feature subset for the discrimination of FFSNs recorded with the datasets we used.
引用
收藏
页数:6
相关论文
共 50 条
  • [31] Monitoring a Fast Flux botnet using recursive and passive DNS: A case study
    Mahjoub, Dhia
    2013 ECRIME RESEARCHERS SUMMIT (ECRS), 2013,
  • [32] Botnet detection used fast-flux technique, based on adaptive dynamic evolving spiking neural network algorithm
    Almomani, Ammar
    Al-Nawasrah, Ahmad
    Alauthman, Mohammad
    Al-Betar, Mohammed Azmi
    Meziane, Farid
    INTERNATIONAL JOURNAL OF AD HOC AND UBIQUITOUS COMPUTING, 2021, 36 (01) : 50 - 65
  • [33] Detection of DNS Tunneling in Mobile Networks Using Machine Learning
    Van Thuan Do
    Engelstad, Paal
    Feng, Boning
    Thanh Van Do
    INFORMATION SCIENCE AND APPLICATIONS 2017, ICISA 2017, 2017, 424 : 221 - 230
  • [34] Unsupervised Feature Propagation for Fast Video Object Detection Using Generative Adversarial Networks
    Zhang, Xuan
    Han, Guangxing
    He, Wenduo
    MULTIMEDIA MODELING (MMM 2020), PT I, 2020, 11961 : 617 - 627
  • [35] Real-Time Detection of Fast Flux Service Networks
    Caglayan, Alper
    Toothaker, Mike
    Drapeau, Dan
    Burke, Dustin
    Eaton, Gerry
    CATCH 2009: CYBERSECURITY APPLICATIONS AND TECHNOLOGY CONFERENCE FOR HOMELAND SECURITY, PROCEEDINGS, 2009, : 285 - 292
  • [36] Performance Analysis of Various Feature Sets for Malaria-Infected Erythrocyte Detection
    Devi, Salam Shuleenda
    Singh, Ngangbam Herojit
    Laskar, Rabul Hussain
    SOFT COMPUTING FOR PROBLEM SOLVING, SOCPROS 2018, VOL 2, 2020, 1057 : 275 - 283
  • [37] Driver Drowsiness Detection System Based on Feature Representation Learning Using Various Deep Networks
    Park, Sanghyuk
    Pan, Fei
    Kang, Sunghun
    Yoo, Chang D.
    COMPUTER VISION - ACCV 2016 WORKSHOPS, PT III, 2017, 10118 : 154 - 164
  • [38] Fast outlier detection using rough sets theory
    Shaari, F.
    Bakar, A. A.
    Hamdan, A. R.
    DATA MINING IX: DATA MINING, PROTECTION, DETECTION AND OTHER SECURITY TECHNOLOGIES, 2008, 40 : 25 - 34
  • [39] Fast Flux Module Detection Using Matroid Theory
    Mueller, Arne C.
    Bruggeman, Frank J.
    Olivier, Brett G.
    Stougie, Leen
    RESEARCH IN COMPUTATIONAL MOLECULAR BIOLOGY, RECOMB2014, 2014, 8394 : 192 - 206
  • [40] Fast Flux Module Detection Using Matroid Theory
    Reimers, Arne C.
    Bruggeman, Frank J.
    Olivier, Brett G.
    Stougie, Leen
    JOURNAL OF COMPUTATIONAL BIOLOGY, 2015, 22 (05) : 414 - 424