Fast and Accurate Identification of Active Recursive Domain Name Servers in high-speed Network

刘晓梅  孙永  黄彩云  邹学强  秦志光 



ABSTRACT: Fast and accurate identi cation of active recursive domain name servers (RDNS) is a fundamental step to evaluate security risk degrees of DNS systems. Much identi cation work have been proposed based on network trac measurement technology. Even though identifying RDNS accurately, they waste huge network resources, and fail to obtain host activity and distinguish between direct and indirect RDNS. In this paper, we proposed an approach to identify direct
and forward RDNS based on our three key insights on their request-response behaviors, and proposed an approach to identify indirect RDNS based on CNAME redirect behaviors. To work in high-speed backbone networks, we further proposed an online connectivity estimation algorithm to obtain estimated values used in our identi cation approaches. According to our experiments, we can identify RDNS with a high accuracy by selecting the reasonable thresholds. The accuracy of identifying direct and forward RDNS can reach 89%. The accuracy of identifying indirect RDNS can reach 90%. Moreover, our work is capable of real-time analyzing high speed backbone tracs.
Keywords: evaluate security risk degrees, recursive nameservers, connectivity estimation



首页
团队介绍
发展历史
组织结构
MESA大事记
新闻中心
通知
组内动态
科研成果
专利
论文
项目
获奖
软著
人才培养
MESA毕业生
MESA在读生
MESA员工
招贤纳士
走进MESA
学长分享
招聘通知
招生宣传
知识库
文章
地址:北京市朝阳区华严北里甲22号楼五层 | 邮编:100029
邮箱:nelist@iie.ac.cn
京ICP备15019404号-1