Passive OS Fingerprinting by DNS Traffic Analysis
Passive OS Fingerprinting by DNS Traffic Analysis
复制标题
DOI:
10.1109/aina.2013.119
复制
发表时间:
2013-03
期刊:
影响因子:
--
通讯作者:
T. Matsunaka;A. Yamada;A. Kubota
中科院分区:
文献类型:
--
作者:
T. Matsunaka;A. Yamada;A. Kubota
In this paper, we propose a new passive OS fingerprinting method which only requires DNS traffic analysis. The method utilizes characteristics on DNS queries specific to each OS, e.g. unique domain names, query patterns, time interval etc. The method can estimate the number of devices with each OS from the number of queries by utilizing the characteristics of the time interval patterns. The method considers the likelihood of irregular events that some queries are sent at less than regular time intervals, and some other queries are sent at more than regular time intervals. We analyze DNS traffic sent by each OS and extract the characteristics for OS fingerprinting. Then, we examine our estimation method by using DNS traffic in our intra-network. According to our examination, some results of our estimation method are close to the results of DHCP fingerprinting.