An Internet-Wide View into DNS Lookup Patterns
نویسندگان
چکیده
This paper analyzes the DNS lookup patterns from a large authoritative top-level domain server and characterizes how the lookup patterns for unscrupulous domains may differ from those for legitimate domains. We examine domains for phishing attacks and spam and malware related domains, and see how these lookup patterns vary in terms of both their temporal and spatial characteristics. We find that malicious domains tend to exhibit more variance in the networks that look up these domains, and we also find that these domains become popular considerably more quickly after their initial registration time. We also note that miscreant domains exhibit distinct clusters, in terms to the networks that look up these domains. The distinct spatial and temporal characteristics of these domains, and their tendency to exhibit similar lookup behavior, suggests that it may be possible to ultimately develop more effective blacklisting techniques based on these differing lookup patterns.
منابع مشابه
Category : Informational February 2006 6 to 4 Reverse DNS Delegation Specification
6to4 Reverse DNS Delegation Specification Status of This Memo This memo provides information for the Internet community. It does not specify an Internet standard of any kind. Distribution of this memo is unlimited. Abstract This memo describes the service mechanism for entering a delegation of DNS servers that provide reverse lookup of 6to4 IPv6 addresses into the 6to4 reverse zone file. The me...
متن کاملThe Contribution of Dns Lookup Costs to Web Ob Ject Retrieval
There are a number of factors that contribute to the performance between clients and servers in the World Wide Web. In this work we have concentrated on the contribution of DNS lookup to the overall Web object retrieval time. We found that the DNS mechanism performed better for popular Web servers than for random Web servers. Performance was better both in terms of local cache hit rates, which ...
متن کاملPreventing DNS Amplification Attacks Using the History of DNS Queries with SDN
Domain Name System (DNS) amplification attack is a sophisticated Distributed Denial of Service (DDoS) attack by sending a huge volume of DNS name lookup requests to open DNS servers with the source address spoofed as a victim host. However, from the point of view of an individual network resource such as DNS server and switch, it is not easy to mitigate such attacks because a distributed attack...
متن کاملDefinitions of Managed Objects for Remote Ping, Traceroute, and Lookup Operations
Status of this Memo This document specifies an Internet standards track protocol for the Internet community, and requests discussion and suggestions for improvements. Please refer to the current edition of the "Internet Official Protocol Standards" (STD 1) for the standardization state and status of this protocol. Distribution of this memo is unlimited. Abstract This memo defines Management Inf...
متن کاملBetter than 1 Hop Lookup Performance with Proactive Caching
High lookup latencies prohibit peer-to-peer overlays from being used in many performance intensive applications, even though they provide self-organization, scalability, and failure resilience. In this paper, we show that lookup performance of structured DHTs can be improved to any desirable constant, even under 1 hop, by controlled proactive replication. By exploiting the popularity distributi...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2010