Detection of Kaminsky DNS Cache Poisoning Attack

Detection of Kaminsky DNS Cache Poisoning Attack
复制标题

Kaminsky DNS 缓存中毒攻击检测

DOI:
10.1109/icinis.2011.18
复制
发表时间:
2011
期刊:
2011 4th International Conference on Intelligent Networks and Intelligent Systems
影响因子:
--
通讯作者:
K. Sugitani
K. Sugitani
中科院分区:
--
文献类型:
--
作者:
Y. Musashi;Masaya Kumagai;S. Kubota;K. Sugitani

文献摘要

被引文献

相似文献

我们统计了2010年1月1日至12月31日,某高校校园网从Internet到顶级域DNS服务器的入站标准DNS解析流量。结果表明:(1)通过观察基于唯一源IP地址的DNS查询请求报文流量熵的快速下降和基于唯一DNS查询关键字的流量熵的显著增加,我们发现了5次卡明斯基DNS缓存中毒(Kaminsky)攻击。(2)采用1 ~ 40的阈值范围计算当前查询关键字与最后一个查询关键字之间的限制Damerau-Levenshtein距离(限制编辑距离),在检测方法的得分变化中发现了9种卡明斯基攻击。因此,基于受限Damerau-Levenshtein距离的检测技术有可能检测到Kaminsky攻击。
We statistically investigated the total inbound standard DNS resolution traffic from the Internet to the top domain DNS server in a university campus network through January 1st to December 31st, 2010. The following results are obtained: (1) We found five Kaminsky DNS Cache Poisoning (Kaminsky) attacks in observation of rapid decrease in the unique source IP address based entropy of the DNS query request packet traffic and significant increase in the unique DNS query keyword based one. (2) Also, we found nine Kaminsky attacks in the score changes for detection method using the calculated restricted Damerau-Levenshtein distance (restricted edit distance) between the observed current query keyword and the last one by employing both threshold ranges through 1 to 40. Therefore, it has a possibility that the restricted Damerau-Levenshtein distance based detection technology can detect the Kaminsky attacks.