DNS-Class: immediate classification of IP flows using DNS
نویسندگان
چکیده
In the last years, we have witnessed a tremendous growth of the Internet, especially in terms of the amount of data being transmitted through the networks and new protocols being implemented. This poses a challenge for network administrators, who need adequate traffic classification tools for network management, e.g. to implement Quality of Service (QoS) requirements. In this paper, we employ real traffic traces to assess the usefulness of Domain Name System (DNS) information for traffic classification. We show that by inspecting DNS packets, it is possible to immediately classify a highly significant portion of the traffic. We present DNS-Class: an innovative, fast, and reliable flow-based classifier that on average yields 99.2% of True Positives with <0.1% of False Positives. We argue that DNS-Class represents an important development in the field of traffic classification, and that it can be a major element of a modular traffic classification system. Copyright c © 0000 John Wiley & Sons, Ltd.
منابع مشابه
Evaluation of Recirculation Time in Bubble Train Flow by Using Direct Numerical Simulation
In this research, hydrodynamics of the Bubble Train Flows (BTF) in circular capillaries has been investigated by Direct Numerical Simulation (DNS).The Volume of Fluid Based (VOF) interface tracking method and streamwise direction periodic boundary conditions has been applied. The results show that there exists an appropriate agreement between DNS and experimental correlation results. The re...
متن کاملDetection of DNS Traffic Anomalies in Large Networks
Almost every Internet communication is preceded by a translation of a DNS name to an IP address. Therefore monitoring of DNS traffic can effectively extend capabilities of current methods for network traffic anomaly detection. In order to effectively monitor this traffic, we propose a new flow metering algorithm that saves resources of a flow exporter. Next, to show benefits of the DNS traffic ...
متن کاملThe Role of Direct Numerical Simulations in Validation and Verification
The role of direct numerical simulations (DNS) of multiphase flows, where all continuum length and time scales are fully resolved, in validation and verification of models for the average flow, is discussed. Although DNS are usually limited to relatively small problems and are generally impractical for predictions of full-scale multiphase systems, DNS offer unprecedented data and insight. Indee...
متن کاملDetecting Active Bot Networks Based on DNS Traffic Analysis
Abstract—One of the serious threats to cyberspace is the Bot networks or Botnets. Bots are malicious software that acts as a network and allows hackers to remotely manage and control infected computer victims. Given the fact that DNS is one of the most common protocols in the network and is essential for the proper functioning of the network, it is very useful for monitoring, detecting and redu...
متن کاملDNS Resolvers and their Clients
The Domain Name System (DNS) performs an essential Internet duty: the translation of host names, which are convenient for humans, into IP addresses, which are used to route packets. To do so, an application on an end-user’s system must contact a DNS resolver to perform these translations. While the user’s system may run a DNS resolver locally, many use an ISP resolver (sometimes called a DNS ca...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- Int. Journal of Network Management
دوره 24 شماره
صفحات -
تاریخ انتشار 2014