Fast-flux Service Networks Real-time Detection via Localized Spatial Geolocation Modeling
碩士 === 國立臺灣科技大學 === 資訊工程系 === 100 === Fast-Flux Service Networks (FFSNs), broadly used by botnets, are an evasive technique for conducting malicious behavior via rapid activities. FFSN detection easily fails in the case of poor performance and causes a high incidence of false positives due to the si...
Main Authors: | , |
---|---|
Other Authors: | |
Format: | Others |
Language: | en_US |
Published: |
2012
|
Online Access: | http://ndltd.ncl.edu.tw/handle/5ku698 |
id |
ndltd-TW-100NTUS5392018 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-TW-100NTUS53920182019-05-15T20:43:22Z http://ndltd.ncl.edu.tw/handle/5ku698 Fast-flux Service Networks Real-time Detection via Localized Spatial Geolocation Modeling 基於區域性及空間性之地理定位概念即時偵測Fast-flux網路服務的系統與方法 Horng-Tzer Wang 王宏澤 碩士 國立臺灣科技大學 資訊工程系 100 Fast-Flux Service Networks (FFSNs), broadly used by botnets, are an evasive technique for conducting malicious behavior via rapid activities. FFSN detection easily fails in the case of poor performance and causes a high incidence of false positives due to the similarity of an FFSN to a content distribution network (CDN), a normal behavior for load balance. In this study, we propose a localized spatial geolocation detection (LSGD) system for identifying FFSNs in real time. We believe that the grid distribution of LSGD possesses a precise spatial locating capability for profiling the spatial relations among IP address resolutions. Furthermore, autonomous system numbers (ASNs) are used for enhancing localized geographic characteristics. The proposed system, incorporating LSGD, ASNs, and the domain name system (DNS), can respond well to identify potential FFSNs. The results of our experiment show that the proposed LSGD system has a better detection capability than state-of-the-art spatial or temporal detection approaches, with a lower false positive rate in real-time detection than the approach based on a spatial snapshot alone. Hahn-Ming Lee 李漢銘 2012 學位論文 ; thesis 98 en_US |
collection |
NDLTD |
language |
en_US |
format |
Others
|
sources |
NDLTD |
description |
碩士 === 國立臺灣科技大學 === 資訊工程系 === 100 === Fast-Flux Service Networks (FFSNs), broadly used by botnets, are an evasive technique for conducting malicious behavior via rapid activities. FFSN detection easily fails in the case of poor performance and causes a high incidence of false positives due to the similarity of an FFSN to a content distribution network (CDN), a normal behavior for load balance. In this study, we propose a localized spatial geolocation detection (LSGD) system for identifying FFSNs in real time. We believe that the grid distribution of LSGD possesses a precise spatial locating capability for profiling the spatial relations among IP address resolutions. Furthermore, autonomous system numbers (ASNs) are used for enhancing localized geographic characteristics. The proposed system, incorporating LSGD, ASNs, and the domain name system (DNS), can respond well to identify potential FFSNs. The results of our experiment show that the proposed LSGD system has a better detection capability than state-of-the-art spatial or temporal detection approaches, with a lower false positive rate in real-time detection than the approach based on a spatial snapshot alone.
|
author2 |
Hahn-Ming Lee |
author_facet |
Hahn-Ming Lee Horng-Tzer Wang 王宏澤 |
author |
Horng-Tzer Wang 王宏澤 |
spellingShingle |
Horng-Tzer Wang 王宏澤 Fast-flux Service Networks Real-time Detection via Localized Spatial Geolocation Modeling |
author_sort |
Horng-Tzer Wang |
title |
Fast-flux Service Networks Real-time Detection via Localized Spatial Geolocation Modeling |
title_short |
Fast-flux Service Networks Real-time Detection via Localized Spatial Geolocation Modeling |
title_full |
Fast-flux Service Networks Real-time Detection via Localized Spatial Geolocation Modeling |
title_fullStr |
Fast-flux Service Networks Real-time Detection via Localized Spatial Geolocation Modeling |
title_full_unstemmed |
Fast-flux Service Networks Real-time Detection via Localized Spatial Geolocation Modeling |
title_sort |
fast-flux service networks real-time detection via localized spatial geolocation modeling |
publishDate |
2012 |
url |
http://ndltd.ncl.edu.tw/handle/5ku698 |
work_keys_str_mv |
AT horngtzerwang fastfluxservicenetworksrealtimedetectionvialocalizedspatialgeolocationmodeling AT wánghóngzé fastfluxservicenetworksrealtimedetectionvialocalizedspatialgeolocationmodeling AT horngtzerwang jīyúqūyùxìngjíkōngjiānxìngzhīdelǐdìngwèigàiniànjíshízhēncèfastfluxwǎnglùfúwùdexìtǒngyǔfāngfǎ AT wánghóngzé jīyúqūyùxìngjíkōngjiānxìngzhīdelǐdìngwèigàiniànjíshízhēncèfastfluxwǎnglùfúwùdexìtǒngyǔfāngfǎ |
_version_ |
1719104628725907456 |