Fast-Flux Service Networks (FFSN) Detection Based on DNS MX Record

碩士 === 國立雲林科技大學 === 資訊管理系碩士班 === 100 === During recent decades, the explosive development of the Internet brings a remarkable advance in information exchange. Hence, people’s daily life and commercial activities rely on the Internet much tremendously. More and more hackers try to gain enormous illeg...

Full description

Bibliographic Details
Main Authors: Tsung-en Huang, 黃宗恩
Other Authors: Tung-ming Koo
Format: Others
Language:zh-TW
Published: 2012
Online Access:http://ndltd.ncl.edu.tw/handle/67451821200819479758
id ndltd-TW-100YUNT5396017
record_format oai_dc
spelling ndltd-TW-100YUNT53960172015-10-13T21:55:45Z http://ndltd.ncl.edu.tw/handle/67451821200819479758 Fast-Flux Service Networks (FFSN) Detection Based on DNS MX Record 以網域名稱服務之郵件交換紀錄為基礎偵測動態惡意域名服務網路 Tsung-en Huang 黃宗恩 碩士 國立雲林科技大學 資訊管理系碩士班 100 During recent decades, the explosive development of the Internet brings a remarkable advance in information exchange. Hence, people’s daily life and commercial activities rely on the Internet much tremendously. More and more hackers try to gain enormous illegal profits by such illegitimate invasion and attack approaches. For instance, Fast-Flux Service Networks is one of emerging attack technologies, which is used to invade the system through combining the RR-DNS technology (Round Robin DNS) of DNS. Fast-Flux can protect malicious websites by keeping changing the IP address of the Mothership. In most cases, naïve users’ computers are usually the attack targets so the damage is getting worse with each passing day. Therefore, this study uses FFSN characterization and original features as detection patterns to construct a detection system. The data from ATLAS and ALEXA are tested to evaluate the detection rate and accuracy of the proposed system. Finally, through the analysis of the detection effectiveness after features mapping, the best solution can be found as the future detection pattern. Tung-ming Koo 古東明 2012 學位論文 ; thesis 73 zh-TW
collection NDLTD
language zh-TW
format Others
sources NDLTD
description 碩士 === 國立雲林科技大學 === 資訊管理系碩士班 === 100 === During recent decades, the explosive development of the Internet brings a remarkable advance in information exchange. Hence, people’s daily life and commercial activities rely on the Internet much tremendously. More and more hackers try to gain enormous illegal profits by such illegitimate invasion and attack approaches. For instance, Fast-Flux Service Networks is one of emerging attack technologies, which is used to invade the system through combining the RR-DNS technology (Round Robin DNS) of DNS. Fast-Flux can protect malicious websites by keeping changing the IP address of the Mothership. In most cases, naïve users’ computers are usually the attack targets so the damage is getting worse with each passing day. Therefore, this study uses FFSN characterization and original features as detection patterns to construct a detection system. The data from ATLAS and ALEXA are tested to evaluate the detection rate and accuracy of the proposed system. Finally, through the analysis of the detection effectiveness after features mapping, the best solution can be found as the future detection pattern.
author2 Tung-ming Koo
author_facet Tung-ming Koo
Tsung-en Huang
黃宗恩
author Tsung-en Huang
黃宗恩
spellingShingle Tsung-en Huang
黃宗恩
Fast-Flux Service Networks (FFSN) Detection Based on DNS MX Record
author_sort Tsung-en Huang
title Fast-Flux Service Networks (FFSN) Detection Based on DNS MX Record
title_short Fast-Flux Service Networks (FFSN) Detection Based on DNS MX Record
title_full Fast-Flux Service Networks (FFSN) Detection Based on DNS MX Record
title_fullStr Fast-Flux Service Networks (FFSN) Detection Based on DNS MX Record
title_full_unstemmed Fast-Flux Service Networks (FFSN) Detection Based on DNS MX Record
title_sort fast-flux service networks (ffsn) detection based on dns mx record
publishDate 2012
url http://ndltd.ncl.edu.tw/handle/67451821200819479758
work_keys_str_mv AT tsungenhuang fastfluxservicenetworksffsndetectionbasedondnsmxrecord
AT huángzōngēn fastfluxservicenetworksffsndetectionbasedondnsmxrecord
AT tsungenhuang yǐwǎngyùmíngchēngfúwùzhīyóujiànjiāohuànjìlùwèijīchǔzhēncèdòngtàièyìyùmíngfúwùwǎnglù
AT huángzōngēn yǐwǎngyùmíngchēngfúwùzhīyóujiànjiāohuànjìlùwèijīchǔzhēncèdòngtàièyìyùmíngfúwùwǎnglù
_version_ 1718070277961678848