SFDS: A Self-Feedback Detection System for DNS Hijacking Based on Multi-Protocol Cross Validation

黄彩云  张鹏  孙永  朱宇佳  刘洋 



With the rapid growth of the Internet, concerns about the security of Domain Name System (DNS) have become prominent. DNS Hijacking is a typical threat which manipulates DNS resource records (RRs) to make users obtain wrong website server IPs through Cache Poisoning or Man-in-the-middle attack.

In this paper, we propose a Self-Feedback Detection System (SFDS) deployed at Local Area Network (LAN) Gateway to protect users from visiting the wrong websites. SFDS: (i)finds the incorrect (Domain, IP) tuples in real-time to provide a correct (Domain, IP) tuple list for users, (ii)utilizes a multi-protocol cross validation method to verify suspicious (Domain, IP) tuples, (iii) applies self-feedback mechanism to calculate the correctness probabilities of (Domain, IP) iteratively.

We show that in real circumstance for two weeks, SFDS can find almost 1300 correct (Domain, IP) tuples for one domain on average in one day. And SFDS is effective with accuracy approximately 100% by our experiments.





首页
团队介绍
发展历史
组织结构
MESA大事记
新闻中心
通知
组内动态
科研成果
专利
论文
项目
获奖
软著
人才培养
MESA毕业生
MESA在读生
MESA员工
招贤纳士
走进MESA
学长分享
招聘通知
招生宣传
知识库
文章
地址:北京市朝阳区华严北里甲22号楼五层 | 邮编:100029
邮箱:nelist@iie.ac.cn
京ICP备15019404号-1