Mining agile DNS traffic using graph analysis for cybercrime detection

Mining agile DNS traffic using graph analysis for cybercrime detection
复制标题

使用图形分析挖掘敏捷 DNS 流量以进行网络犯罪检测

DOI:
10.1016/j.comnet.2016.02.009
复制
发表时间:
2016
期刊:
Comput. Networks
影响因子:
--
通讯作者:
A. Pescapé
A. Pescapé
中科院分区:
--
文献类型:
--
作者:
A. Berger;A. D'Alconzo;W. Gansterer;A. Pescapé

文献摘要

被引文献

相似文献

我们考虑对网络流量数据进行分析,以识别高度敏捷的DNS模式,这些模式被广泛认为是网络犯罪的标志。与相关方法相比,我们的方法能够明确区分良性互联网服务和犯罪网站的个人,固有的敏捷性。尽管一些良性服务使用大量地址,但由于操作要求和与某些内容分发网络的合同协议,它们仅限于IP地址的子集。我们将讨论DNSMap,这是一个分析观察到的DNS流量的系统,并不断了解哪些DNS托管在哪些IP地址上。随着时间的推移,任何重大变化都被映射到二分图,然后进一步修剪网络犯罪活动。图形分析可以检测CDN和IP之间的传递关系,并揭示恶意CDN和托管它们的IP地址的集群。我们开发了一个原型系统,它是专为实时分析,不需要昂贵的分类器再培训,没有过多的白名单。我们评估我们的系统使用大型数据集从ISP与几个100,000客户,并证明,即使是中等敏捷的犯罪网站可以可靠地检测到,几乎立即。
We consider the analysis of network traffic data for identifying highly agile DNS patterns which are widely considered indicative for cybercrime. In contrast to related approaches, our methodology is capable of explicitly distinguishing between the individual, inherent agility of benign Internet services and criminal sites. Although some benign services use a large number of addresses, they are confined to a subset of IP addresses, due to operational requirements and contractual agreements with certain Content Distribution Networks. We discuss DNSMap, a system which analyzes observed DNS traffic, and continuously learns which FQDNs are hosted on which IP addresses. Anysignificantchanges over time are mapped to bipartite graphs, which are then further pruned for cybercrime activity. Graph analysis enables the detection of transitive relations between FQDNs and IPs, and reveals clusters of malicious FQDNs and IP addresses hosting them. We developed a prototype system which is designed for realtime analysis, requires no costly classifier retraining, and no excessive whitelisting. We evaluate our system using large data sets from an ISP with several 100,000 customers, and demonstrate that even moderately agile criminal sites can be detected reliably and almost immediately.