DNS Intrusion Detection (DID) — A SNORT-based solution to detect DNS Amplification and DNS Tunneling attacks

域名系统 服务拒绝攻击 计算机科学 入侵检测系统 计算机安全 互联网 计算机网络 僵尸网络 操作系统
作者
Sanjay Adiwal,Balaji Rajendran,D. Pushparaj Shetty,Sithu D. Sudarsan
标识
DOI:10.1016/j.fraope.2023.100010
摘要

Domain Name System (DNS) plays a critical role in the Internet ecosystem, translating numerical IP addresses to memorable domain names and vice versa. The malicious user targets DNS by taking advantage of vulnerabilities in DNS. The most complex attacks in the DNS attacks vector include Distributed Denial of Service (DDoS) based DNS amplification attacks and sophisticated DNS tunneling attacks. An Intrusion Detection System (IDS) is a solution available to monitor the traffic for intrusion in the network but not exclusively for DNS intrusions. In this research paper, we present – DNS Intrusion Detection (DID), a system integrated into SNORT – a prominent open-source IDS, to detect major DNS-related attacks. We developed novel IDS signatures for various tools used in the tunneling, amplification, and DoS attacks and added them to the existing ruleset file of IDS to detect DNS-based intrusions. Our approach successfully identifies empirical DNS attacks carried out by various known tools available over the Internet. Evaluation of DID showed a high detection rate and a very low false-positive rate.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
更新
PDF的下载单位、IP信息已删除 (2025-6-4)

科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
霸气小欧发布了新的文献求助20
刚刚
小李子完成签到,获得积分10
刚刚
科研虫儿完成签到,获得积分10
1秒前
1秒前
华仔应助PPPPPP采纳,获得10
1秒前
2秒前
鹏鹏完成签到,获得积分10
3秒前
3秒前
Sunsets完成签到 ,获得积分10
4秒前
5秒前
5秒前
5秒前
bkagyin应助科研通管家采纳,获得10
5秒前
科研通AI2S应助科研通管家采纳,获得10
5秒前
BrillSpikes完成签到,获得积分10
5秒前
李爱国应助科研通管家采纳,获得10
5秒前
搜集达人应助oceana采纳,获得10
5秒前
贰拾完成签到,获得积分20
5秒前
充电宝应助科研通管家采纳,获得10
5秒前
搜集达人应助科研通管家采纳,获得10
5秒前
华仔应助科研通管家采纳,获得10
5秒前
上官若男应助科研通管家采纳,获得10
5秒前
脑洞疼应助科研通管家采纳,获得10
5秒前
5秒前
5秒前
5秒前
丰富向松发布了新的文献求助10
5秒前
Jiang应助科研通管家采纳,获得10
6秒前
6秒前
SYLH应助科研通管家采纳,获得10
6秒前
在水一方应助汉堡包采纳,获得10
6秒前
6秒前
LYSM应助科研通管家采纳,获得10
6秒前
6秒前
6秒前
朱建军应助科研通管家采纳,获得10
6秒前
6秒前
6秒前
SciGPT应助科研通管家采纳,获得10
6秒前
6秒前
高分求助中
Ophthalmic Equipment Market by Devices(surgical: vitreorentinal,IOLs,OVDs,contact lens,RGP lens,backflush,diagnostic&monitoring:OCT,actorefractor,keratometer,tonometer,ophthalmoscpe,OVD), End User,Buying Criteria-Global Forecast to2029 2000
A new approach to the extrapolation of accelerated life test data 1000
Cognitive Neuroscience: The Biology of the Mind (Sixth Edition) 1000
ACSM’s Guidelines for Exercise Testing and Prescription, 12th edition 588
Christian Women in Chinese Society: The Anglican Story 500
A Preliminary Study on Correlation Between Independent Components of Facial Thermal Images and Subjective Assessment of Chronic Stress 500
Technical Brochure TB 814: LPIT applications in HV gas insulated switchgear 500
热门求助领域 (近24小时)
化学 材料科学 医学 生物 工程类 有机化学 生物化学 物理 内科学 纳米技术 计算机科学 化学工程 复合材料 遗传学 基因 物理化学 催化作用 冶金 细胞生物学 免疫学
热门帖子
关注 科研通微信公众号,转发送积分 3960721
求助须知:如何正确求助?哪些是违规求助? 3506928
关于积分的说明 11132948
捐赠科研通 3239182
什么是DOI,文献DOI怎么找? 1790081
邀请新用户注册赠送积分活动 872130
科研通“疑难数据库(出版商)”最低求助积分说明 803128