Towards passive DNS software fingerprinting

Towards passive DNS software fingerprinting
复制标题

DOI:
10.1145/2534142.2534144
复制
发表时间:
2013-11
期刊:
--
影响因子:
--
通讯作者:
Ruetee Chitpranee;K. Fukuda
Ruetee Chitpranee;K. Fukuda
中科院分区:
其他
文献类型:
--
作者:
Ruetee Chitpranee;K. Fukuda

文献摘要

相似文献

本文提出了一种替代指纹技术,以确定DNS软件上运行的缓存解析器在被动收集的流量跟踪。利用该方法,不需要在测量期间发送附加查询,这与依赖于探测并且可能由于防火墙过滤或拒绝响应而无效的现有技术不同。我们首先仔细检查特定仿真的DNS查询模式,并从实验中提取15条启发式规则来识别典型软件(即,BIND、Unbound和Windows Server)。接下来,我们使用具有地面实况数据的真实的骨干网流量跟踪来证明规则的有效性。结果显示,与地面实况相比,准确率为99%。此外,地面实况中78%的未知主机可以被识别。
This paper presents an alternative fingerprinting technique to identify DNS software running on caching resolvers in passively collected traffic traces. With this method, it is not required to send additional queries during the measurement, unlike existing techniques that rely on probing and may not be effective due to firewall filtering or refused responses. We first carefully examine DNS query patterns upon specific emulation and extract 15 heuristic rules from the experiment to identify typical software (i.e., BIND, Unbound and Windows Server). We next demonstrate the effectiveness of the rules using real backbone traffic traces with ground truth data. The results show 99% accuracy compared to the ground truth. Furthermore, 78% of unknown hosts in the ground truth can be identified.