Detection of Kaminsky DNS Cache Poisoning Attack
Detection of Kaminsky DNS Cache Poisoning Attack
复制标题
Kaminsky DNS 缓存中毒攻击检测
DOI:
10.1109/icinis.2011.18
复制
发表时间:
2011
期刊:
影响因子:
--
通讯作者:
K. Sugitani
中科院分区:
文献类型:
--
作者:
Y. Musashi;Masaya Kumagai;S. Kubota;K. Sugitani
We statistically investigated the total inbound standard DNS resolution traffic from the Internet to the top domain DNS server in a university campus network through January 1st to December 31st, 2010. The following results are obtained: (1) We found five Kaminsky DNS Cache Poisoning (Kaminsky) attacks in observation of rapid decrease in the unique source IP address based entropy of the DNS query request packet traffic and significant increase in the unique DNS query keyword based one. (2) Also, we found nine Kaminsky attacks in the score changes for detection method using the calculated restricted Damerau-Levenshtein distance (restricted edit distance) between the observed current query keyword and the last one by employing both threshold ranges through 1 to 40. Therefore, it has a possibility that the restricted Damerau-Levenshtein distance based detection technology can detect the Kaminsky attacks.