IDNS: A High-Performance Model for Identification of DNS Infrastructures on Large-scale Traffic

黄彩云  朱宇佳  刘庆云  孙永 



Domain Name System (DNS) is indispensable in a large number of network applications. Identifying DNS infrastructures into different roles hierarchically is highly desired for a variety of purposes such as network management and threat evaluation. However, traditional measurements almost all depend on active scanning without considering dynamic packet-level features of different DNS infrastructures.

In this paper, we propose a high-performance model IDNS (Identifying DNS) based on passive measurement. IDNS: (i) extracts single-packet field features (SFF) and multi-packet statistical features (MSF) from DNS traffic, (ii) utilizes an estimation algorithm to calculate MSF for satisfying online processing speed, (iii) applies several classifiers in Ensemble Learning and Incremental Learning. We perform an extensive evaluation based on a large volume of DNS queries and responses collected from one ISP. The evaluation results demonstrate that the best classifiers in Ensemble Learning can reach 90% accuracy rate while the classifier in Incremental Learning can reach 80% with the highest scalability.

(Domain, IP) tuple list for users, (ii)utilizes a multi-protocol cross validation method to verify suspicious (Domain, IP) tuples, (iii) applies self-feedback mechanism to calculate the correctness probabilities of (Domain, IP) iteratively.

We show that in real circumstance for two weeks, SFDS can find almost 1300 correct (Domain, IP) tuples for one domain on average in one day. And SFDS is effective with accuracy approximately 100% by our experiments.





首页
团队介绍
发展历史
组织结构
MESA大事记
新闻中心
通知
组内动态
科研成果
专利
论文
项目
获奖
软著
人才培养
MESA毕业生
MESA在读生
MESA员工
招贤纳士
走进MESA
学长分享
招聘通知
招生宣传
知识库
文章
地址:北京市朝阳区华严北里甲22号楼五层 | 邮编:100029
邮箱:nelist@iie.ac.cn
京ICP备15019404号-1