Passive OS Fingerprinting by DNS Traffic Analysis

Passive OS Fingerprinting by DNS Traffic Analysis
复制标题

DOI:
10.1109/aina.2013.119
复制
发表时间:
2013-03
期刊:
2013 IEEE 27th International Conference on Advanced Information Networking and Applications (AINA)
影响因子:
--
通讯作者:
T. Matsunaka;A. Yamada;A. Kubota
T. Matsunaka;A. Yamada;A. Kubota
中科院分区:
其他
文献类型:
--
作者:
T. Matsunaka;A. Yamada;A. Kubota

文献摘要

被引文献

相似文献

在本文中,我们提出了一种新的被动操作系统指纹识别方法,该方法只需要对DNS流量进行分析。该方法利用特定于每个操作系统的关于DNS查询的特征,例如唯一域名、查询模式、时间间隔等。该方法可以通过利用时间间隔模式的特征从查询的数量估计每个操作系统的设备数量。该方法考虑了不规则事件的可能性,即一些查询以小于规则的时间间隔发送,而另一些查询以大于规则的时间间隔发送。我们分析每个操作系统发送的DNS流量,提取用于操作系统指纹识别的特征。然后,我们使用内部网络中的DNS流量来检查我们的估计方法。根据我们的检验,我们的估计方法的某些结果与动态主机配置协议指纹图谱的结果接近。
In this paper, we propose a new passive OS fingerprinting method which only requires DNS traffic analysis. The method utilizes characteristics on DNS queries specific to each OS, e.g. unique domain names, query patterns, time interval etc. The method can estimate the number of devices with each OS from the number of queries by utilizing the characteristics of the time interval patterns. The method considers the likelihood of irregular events that some queries are sent at less than regular time intervals, and some other queries are sent at more than regular time intervals. We analyze DNS traffic sent by each OS and extract the characteristics for OS fingerprinting. Then, we examine our estimation method by using DNS traffic in our intra-network. According to our examination, some results of our estimation method are close to the results of DHCP fingerprinting.