Accurate DNS query characteristics estimation via active probing

Accurate DNS query characteristics estimation via active probing
复制标题

DOI:
10.1016/j.jnca.2014.09.016
复制
发表时间:
2015
期刊:
J. Netw. Comput. Appl.
影响因子:
--
通讯作者:
Xiaobo Ma;Junjie Zhang;Zhenhua Li;Jianfeng Li;Jing Tao;X. Guan;John C.S. Lui;D. Towsley
Xiaobo Ma;Junjie Zhang;Zhenhua Li;Jianfeng Li;Jing Tao;X. Guan;John C.S. Lui;D. Towsley
中科院分区:
其他
文献类型:
--
作者:
Xiaobo Ma;Junjie Zhang;Zhenhua Li;Jianfeng Li;Jing Tao;X. Guan;John C.S. Lui;D. Towsley

文献摘要

相似文献

域名系统(DNS)作为当今Internet的隐藏骨干,为几乎所有的网络应用提供域名解析服务。为了利用DNS查询信息进行流量工程或用户行为分析,近年来提出了被动捕获和主动探测技术。尽管被动捕获技术可以完全了解DNS行为,但其管理成本过高,并导致其大规模和协作部署的巨大隐私问题。相比之下,主动探测技术克服了这些局限性,提供了广泛的和隐私保护的DNS查询分析的细粒度DNS行为的限制可见性的成本。本文的目的是准确地估计DNS查询的DNS缓存活动的基础上,可以通过主动探测大规模的管理成本可以忽略不计,并最大限度地减少隐私问题的特点。具体来说,我们做了三个贡献:(1)我们提出了一个新的解决方案,它集成了更新理论的DNS缓存公式和超指数分布模型。该解决方案提供了很大的灵活性,以模拟各种域;(2)我们执行了大规模的现实世界的DNS跟踪测量,并证明我们的解决方案显着提高了估计精度;(3)我们应用我们的解决方案来估计恶意软件感染的主机人口在远程管理网络。实验结果表明,我们的解决方案可以达到较高的估计精度,并优于现有的方法。
As the hidden backbone of today׳s Internet, the Domain Name System (DNS) provides name resolution service for almost every networked application. To exploit the rich DNS query information for traffic engineering or user behavior analysis, bothpassive capturingandactive probingtechniques have been proposed in recent years. Despite its full visibility of DNS behaviors, thepassive capturingtechnique suffers from prohibitive management cost and results in tremendous privacy concerns towards its large-scale and collaborative deployment. Comparatively, theactive probingtechnique overcomes these limitations, providing broad-view and privacy-preserving DNS query analysis at the cost of constrained visibility of fine-grained DNS behavior. This paper aims to accurately estimate DNS query characteristics based on DNS cache activities, which can be acquired via active probing on a large scale at negligible management cost and minimized privacy concerns. Specifically, we have made three contributions: (1) we propose a novel solution, which integrates the renewal theory-based DNS caching formulation and the hyper-exponential distribution model. The solution offers great flexibility to model various domains; (2) we perform a large-scale real-world DNS trace measurement, and demonstrate that our solution significantly improves the estimation accuracy; (3) we apply our solution to estimate the malware-infected host population in remote management networks. The experimental results have demonstrated that our solution can achieve high estimation accuracy and outperforms the existing method.