ČERMÁK, Milan, Pavel ČELEDA and Jan VYKOPAL. Detection of DNS Traffic Anomalies in Large Networks. In Advances in Communication Networking, Lecture Notes in Computer Science, Vol. 8846. Heidelberg: Springer International Publishing, 2014, p. 215-226. ISBN 978-3-319-13487-1.
Other formats:   BibTeX LaTeX RIS
Basic information
Original name Detection of DNS Traffic Anomalies in Large Networks
Name in Czech Detekce anomálií DNS provozu v rozsáhlých sítích
Authors ČERMÁK, Milan (203 Czech Republic, guarantor, belonging to the institution), Pavel ČELEDA (203 Czech Republic, belonging to the institution) and Jan VYKOPAL (203 Czech Republic, belonging to the institution).
Edition Heidelberg, Advances in Communication Networking, Lecture Notes in Computer Science, Vol. 8846, p. 215-226, 12 pp. 2014.
Publisher Springer International Publishing
Other information
Original language English
Type of outcome Proceedings paper
Field of Study Informatics
Country of publisher Germany
Confidentiality degree is not subject to a state or trade secret
Publication form printed version "print"
WWW URL
RIV identification code RIV/00216224:14610/14:00073236
Organization Ústav výpočetní techniky – Repository – Repository
ISBN 978-3-319-13487-1
ISSN 0302-9743
UT WoS 000354693000020
Keywords (in Czech) systém doménových jmen; DNS; monitoring síťových toků; IPFIX; detekce anomálií; měření síťového provozu
Keywords in English domain name system; DNS; IP flow monitoring; IPFIX; traffic anomaly detection; internet measurements
Links VG20132015103, research and development project.
Changed by Changed by: RNDr. Daniel Jakubík, učo 139797. Changed: 1/9/2020 21:22.
Abstract
Almost every Internet communication is preceded by a translation of a DNS name to an IP address. Therefore monitoring of DNS traffic can effectively extend capabilities of current methods for network traffic anomaly detection. In order to effectively monitor this traffic, we propose a new flow metering algorithm that saves resources of a flow exporter. Next, to show benefits of the DNS traffic monitoring for anomaly detection, we introduce novel detection methods using DNS extended flows. The evaluation of these methods shows that our approach not only reveals DNS anomalies but also scales well in a campus network.
Abstract (in Czech)
Téměř každá síťová komunikace je předcházena překladem doménového jména na IP adresu. Měření a následná analýza DNS provozu může účinně rozšířit schopnosti současných metod pro detekci anomálií v celkovém síťovém provozu. Aby bylo možné tento provoz efektivně sledovat, navrhujeme v článku nový algoritmus pro sběr a export síťových toků šetřicí zdroje exportéru. Dále, abychom ukázali výhody monitorování DNS provozu pro detekci anomálií, představujeme nové detekční metody využívající síťové toky rozšířené o informace z DNS paketů. Z vyhodnocení těchto metod vyplývá, že navržený přístup umožňuje úspěšně detekovat anomálie v DNS provozu a to dokonce i v rozsáhlých, univerzitních sítích.
Type Name Uploaded/Created by Uploaded/Created Rights
dns-analysis-paper-eunice2014.pdf Licence Creative Commons  File version 17/1/2015

Properties

Name
dns-analysis-paper-eunice2014.pdf
Address within IS
https://repozitar.cz/auth/repo/16889/192845/
Address for the users outside IS
https://repozitar.cz/repo/16889/192845/
Address within Manager
https://repozitar.cz/auth/repo/16889/192845/?info
Address within Manager for the users outside IS
https://repozitar.cz/repo/16889/192845/?info
Uploaded/Created
Sat 17/1/2015 00:50

Rights

Right to read
  • anyone on the Internet
Right to upload
 
Right to administer:
  • a concrete person RNDr. Daniel Jakubík, uco 139797
  • a concrete person Mgr. Ľuboš Lunter, uco 143320
Attributes
 
dns-analysis-paper-eunice2014.pdf Licence Creative Commons  File version 1/9/2020

Properties

Name
dns-analysis-paper-eunice2014.pdf
Address within IS
https://repozitar.cz/auth/repo/16889/897683/
Address for the users outside IS
https://repozitar.cz/repo/16889/897683/
Address within Manager
https://repozitar.cz/auth/repo/16889/897683/?info
Address within Manager for the users outside IS
https://repozitar.cz/repo/16889/897683/?info
Uploaded/Created
Tue 1/9/2020 21:22

Rights

Right to read
  • anyone on the Internet
Right to upload
 
Right to administer:
  • a concrete person Mgr. Lucie Vařechová, uco 106253
  • a concrete person RNDr. Daniel Jakubík, uco 139797
  • a concrete person Mgr. Jolana Surýnková, uco 220973
Attributes
 
dns-analysis-presentation-eunice2014.pdf Licence Creative Commons  File version 17/1/2015

Properties

Name
dns-analysis-presentation-eunice2014.pdf
Address within IS
https://repozitar.cz/auth/repo/16889/192844/
Address for the users outside IS
https://repozitar.cz/repo/16889/192844/
Address within Manager
https://repozitar.cz/auth/repo/16889/192844/?info
Address within Manager for the users outside IS
https://repozitar.cz/repo/16889/192844/?info
Uploaded/Created
Sat 17/1/2015 00:50

Rights

Right to read
  • anyone on the Internet
Right to upload
 
Right to administer:
  • a concrete person RNDr. Daniel Jakubík, uco 139797
  • a concrete person Mgr. Ľuboš Lunter, uco 143320
Attributes
 
dns-analysis-presentation-eunice2014.pdf Licence Creative Commons  File version 1/9/2020

Properties

Name
dns-analysis-presentation-eunice2014.pdf
Address within IS
https://repozitar.cz/auth/repo/16889/897684/
Address for the users outside IS
https://repozitar.cz/repo/16889/897684/
Address within Manager
https://repozitar.cz/auth/repo/16889/897684/?info
Address within Manager for the users outside IS
https://repozitar.cz/repo/16889/897684/?info
Uploaded/Created
Tue 1/9/2020 21:22

Rights

Right to read
  • anyone on the Internet
Right to upload
 
Right to administer:
  • a concrete person Mgr. Lucie Vařechová, uco 106253
  • a concrete person RNDr. Daniel Jakubík, uco 139797
  • a concrete person Mgr. Jolana Surýnková, uco 220973
Attributes
 
Print
Add to clipboard Displayed: 30/4/2024 12:20