DNS-Class: immediate classification of IP flows using DNS

نویسندگان

  • Pawel Foremski
  • Christian Callegari
  • Michele Pagano
چکیده

In the last years, we have witnessed a tremendous growth of the Internet, especially in terms of the amount of data being transmitted through the networks and new protocols being implemented. This poses a challenge for network administrators, who need adequate traffic classification tools for network management, e.g. to implement Quality of Service (QoS) requirements. In this paper, we employ real traffic traces to assess the usefulness of Domain Name System (DNS) information for traffic classification. We show that by inspecting DNS packets, it is possible to immediately classify a highly significant portion of the traffic. We present DNS-Class: an innovative, fast, and reliable flow-based classifier that on average yields 99.2% of True Positives with <0.1% of False Positives. We argue that DNS-Class represents an important development in the field of traffic classification, and that it can be a major element of a modular traffic classification system. Copyright c © 0000 John Wiley & Sons, Ltd.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Evaluation of Recirculation Time in Bubble Train Flow by Using Direct Numerical Simulation

In this research, hydrodynamics of the Bubble Train Flows (BTF) in circular capillaries has been investigated by Direct Numerical Simulation (DNS).The Volume of Fluid Based (VOF) interface tracking method and streamwise direction periodic boundary conditions has been applied. The results show that there exists an appropriate agreement between DNS and experimental correlation results. The re...

متن کامل

Detection of DNS Traffic Anomalies in Large Networks

Almost every Internet communication is preceded by a translation of a DNS name to an IP address. Therefore monitoring of DNS traffic can effectively extend capabilities of current methods for network traffic anomaly detection. In order to effectively monitor this traffic, we propose a new flow metering algorithm that saves resources of a flow exporter. Next, to show benefits of the DNS traffic ...

متن کامل

The Role of Direct Numerical Simulations in Validation and Verification

The role of direct numerical simulations (DNS) of multiphase flows, where all continuum length and time scales are fully resolved, in validation and verification of models for the average flow, is discussed. Although DNS are usually limited to relatively small problems and are generally impractical for predictions of full-scale multiphase systems, DNS offer unprecedented data and insight. Indee...

متن کامل

Detecting Active Bot Networks Based on DNS Traffic Analysis

Abstract—One of the serious threats to cyberspace is the Bot networks or Botnets. Bots are malicious software that acts as a network and allows hackers to remotely manage and control infected computer victims. Given the fact that DNS is one of the most common protocols in the network and is essential for the proper functioning of the network, it is very useful for monitoring, detecting and redu...

متن کامل

DNS Resolvers and their Clients

The Domain Name System (DNS) performs an essential Internet duty: the translation of host names, which are convenient for humans, into IP addresses, which are used to route packets. To do so, an application on an end-user’s system must contact a DNS resolver to perform these translations. While the user’s system may run a DNS resolver locally, many use an ISP resolver (sometimes called a DNS ca...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • Int. Journal of Network Management

دوره 24  شماره 

صفحات  -

تاریخ انتشار 2014