Fast-flux Service Networks Real-time Detection via Localized Spatial Geolocation Modeling

碩士 === 國立臺灣科技大學 === 資訊工程系 === 100 === Fast-Flux Service Networks (FFSNs), broadly used by botnets, are an evasive technique for conducting malicious behavior via rapid activities. FFSN detection easily fails in the case of poor performance and causes a high incidence of false positives due to the si...

Full description

Bibliographic Details
Main Authors: Horng-Tzer Wang, 王宏澤
Other Authors: Hahn-Ming Lee
Format: Others
Language:en_US
Published: 2012
Online Access:http://ndltd.ncl.edu.tw/handle/5ku698
id ndltd-TW-100NTUS5392018
record_format oai_dc
spelling ndltd-TW-100NTUS53920182019-05-15T20:43:22Z http://ndltd.ncl.edu.tw/handle/5ku698 Fast-flux Service Networks Real-time Detection via Localized Spatial Geolocation Modeling 基於區域性及空間性之地理定位概念即時偵測Fast-flux網路服務的系統與方法 Horng-Tzer Wang 王宏澤 碩士 國立臺灣科技大學 資訊工程系 100 Fast-Flux Service Networks (FFSNs), broadly used by botnets, are an evasive technique for conducting malicious behavior via rapid activities. FFSN detection easily fails in the case of poor performance and causes a high incidence of false positives due to the similarity of an FFSN to a content distribution network (CDN), a normal behavior for load balance. In this study, we propose a localized spatial geolocation detection (LSGD) system for identifying FFSNs in real time. We believe that the grid distribution of LSGD possesses a precise spatial locating capability for profiling the spatial relations among IP address resolutions. Furthermore, autonomous system numbers (ASNs) are used for enhancing localized geographic characteristics. The proposed system, incorporating LSGD, ASNs, and the domain name system (DNS), can respond well to identify potential FFSNs. The results of our experiment show that the proposed LSGD system has a better detection capability than state-of-the-art spatial or temporal detection approaches, with a lower false positive rate in real-time detection than the approach based on a spatial snapshot alone. Hahn-Ming Lee 李漢銘 2012 學位論文 ; thesis 98 en_US
collection NDLTD
language en_US
format Others
sources NDLTD
description 碩士 === 國立臺灣科技大學 === 資訊工程系 === 100 === Fast-Flux Service Networks (FFSNs), broadly used by botnets, are an evasive technique for conducting malicious behavior via rapid activities. FFSN detection easily fails in the case of poor performance and causes a high incidence of false positives due to the similarity of an FFSN to a content distribution network (CDN), a normal behavior for load balance. In this study, we propose a localized spatial geolocation detection (LSGD) system for identifying FFSNs in real time. We believe that the grid distribution of LSGD possesses a precise spatial locating capability for profiling the spatial relations among IP address resolutions. Furthermore, autonomous system numbers (ASNs) are used for enhancing localized geographic characteristics. The proposed system, incorporating LSGD, ASNs, and the domain name system (DNS), can respond well to identify potential FFSNs. The results of our experiment show that the proposed LSGD system has a better detection capability than state-of-the-art spatial or temporal detection approaches, with a lower false positive rate in real-time detection than the approach based on a spatial snapshot alone.
author2 Hahn-Ming Lee
author_facet Hahn-Ming Lee
Horng-Tzer Wang
王宏澤
author Horng-Tzer Wang
王宏澤
spellingShingle Horng-Tzer Wang
王宏澤
Fast-flux Service Networks Real-time Detection via Localized Spatial Geolocation Modeling
author_sort Horng-Tzer Wang
title Fast-flux Service Networks Real-time Detection via Localized Spatial Geolocation Modeling
title_short Fast-flux Service Networks Real-time Detection via Localized Spatial Geolocation Modeling
title_full Fast-flux Service Networks Real-time Detection via Localized Spatial Geolocation Modeling
title_fullStr Fast-flux Service Networks Real-time Detection via Localized Spatial Geolocation Modeling
title_full_unstemmed Fast-flux Service Networks Real-time Detection via Localized Spatial Geolocation Modeling
title_sort fast-flux service networks real-time detection via localized spatial geolocation modeling
publishDate 2012
url http://ndltd.ncl.edu.tw/handle/5ku698
work_keys_str_mv AT horngtzerwang fastfluxservicenetworksrealtimedetectionvialocalizedspatialgeolocationmodeling
AT wánghóngzé fastfluxservicenetworksrealtimedetectionvialocalizedspatialgeolocationmodeling
AT horngtzerwang jīyúqūyùxìngjíkōngjiānxìngzhīdelǐdìngwèigàiniànjíshízhēncèfastfluxwǎnglùfúwùdexìtǒngyǔfāngfǎ
AT wánghóngzé jīyúqūyùxìngjíkōngjiānxìngzhīdelǐdìngwèigàiniànjíshízhēncèfastfluxwǎnglùfúwùdexìtǒngyǔfāngfǎ
_version_ 1719104628725907456