Detecting Malicious Activity With DNS Backscatter Over Time

Detecting Malicious Activity With DNS Backscatter Over Time
复制标题

DOI:
10.1109/tnet.2017.2724506
复制
发表时间:
2017-08
期刊:
IEEE/ACM Transactions on Networking
影响因子:
--
通讯作者:
K. Fukuda;J. Heidemann;A. Qadeer
K. Fukuda;J. Heidemann;A. Qadeer
中科院分区:
其他
文献类型:
--
作者:
K. Fukuda;J. Heidemann;A. Qadeer

文献摘要

被引文献

相似文献

网络范围内的活动是指一台计算机(发起者)接触许多其他计算机(目标)。活动的动机可能是良性的(邮件列表、内容交付网络和研究扫描)、恶意的(垃圾邮件发送者和安全漏洞扫描器),或者可能是不确定的(广告跟踪器)。了解恶意活动有助于预测攻击,而了解良性活动可以设定基线或描述增长。本文确定域名系统(DNS)的后向散射作为一个新的信息源,网络范围内的活动。反向散射是当目标或中间设备自动查找发起者的域名时引起的反向DNS查询。DNS对处理反向DNS的权威DNS服务器可见。虽然他们看到的后向散射的分数取决于服务器在DNS层次结构中的位置,但我们发现,即使在采样观察中,也会出现触及许多目标的活动。我们使用有关查询者的信息,使用机器学习对发起者活动进行分类。我们的算法具有合理的准确性和精确度(70-80%),如来自三个不同组织的数据所示,这些组织在根或国家级别运行DNS服务器。使用这种技术,我们检查了一个权威机构九个月的活动,以确定扫描趋势,识别对应于Heartbleed的突发事件,以及安全外壳的广泛和连续扫描。
Network-wide activity is when one computer (the originator) touches many others (the targets). Motives for activity may be benign (mailing lists, content-delivery networks, and research scanning), malicious (spammers and scanners for security vulnerabilities), or perhaps indeterminate (ad trackers). Knowledge of malicious activity may help anticipate attacks, and understanding benign activity may set a baseline or characterize growth. This paper identifies domain name system (DNS) backscatter as a new source of information about network-wide activity. Backscatter is the reverse DNS queries caused when targets or middleboxes automatically look up the domain name of the originator. Queries are visible to the authoritative DNS servers that handle reverse DNS. While the fraction of backscatter they see depends on the server’s location in the DNS hierarchy, we show that activity that touches many targets appear even in sampled observations. We use information about the queriers to classify originator activity using machine-learning. Our algorithm has reasonable accuracy and precision (70–80%) as shown by data from three different organizations operating DNS servers at the root or country level. Using this technique, we examine nine months of activity from one authority to identify trends in scanning, identifying bursts corresponding to Heartbleed, and broad and continuous scanning of secure shell.