Fast-Flux Service Networks (FFSN) Detection Based on DNS MX Record
碩士 === 國立雲林科技大學 === 資訊管理系碩士班 === 100 === During recent decades, the explosive development of the Internet brings a remarkable advance in information exchange. Hence, people’s daily life and commercial activities rely on the Internet much tremendously. More and more hackers try to gain enormous illeg...
Main Authors: | , |
---|---|
Other Authors: | |
Format: | Others |
Language: | zh-TW |
Published: |
2012
|
Online Access: | http://ndltd.ncl.edu.tw/handle/67451821200819479758 |
id |
ndltd-TW-100YUNT5396017 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-TW-100YUNT53960172015-10-13T21:55:45Z http://ndltd.ncl.edu.tw/handle/67451821200819479758 Fast-Flux Service Networks (FFSN) Detection Based on DNS MX Record 以網域名稱服務之郵件交換紀錄為基礎偵測動態惡意域名服務網路 Tsung-en Huang 黃宗恩 碩士 國立雲林科技大學 資訊管理系碩士班 100 During recent decades, the explosive development of the Internet brings a remarkable advance in information exchange. Hence, people’s daily life and commercial activities rely on the Internet much tremendously. More and more hackers try to gain enormous illegal profits by such illegitimate invasion and attack approaches. For instance, Fast-Flux Service Networks is one of emerging attack technologies, which is used to invade the system through combining the RR-DNS technology (Round Robin DNS) of DNS. Fast-Flux can protect malicious websites by keeping changing the IP address of the Mothership. In most cases, naïve users’ computers are usually the attack targets so the damage is getting worse with each passing day. Therefore, this study uses FFSN characterization and original features as detection patterns to construct a detection system. The data from ATLAS and ALEXA are tested to evaluate the detection rate and accuracy of the proposed system. Finally, through the analysis of the detection effectiveness after features mapping, the best solution can be found as the future detection pattern. Tung-ming Koo 古東明 2012 學位論文 ; thesis 73 zh-TW |
collection |
NDLTD |
language |
zh-TW |
format |
Others
|
sources |
NDLTD |
description |
碩士 === 國立雲林科技大學 === 資訊管理系碩士班 === 100 === During recent decades, the explosive development of the Internet brings a remarkable advance in information exchange. Hence, people’s daily life and commercial activities rely on the Internet much tremendously. More and more hackers try to gain enormous illegal profits by such illegitimate invasion and attack approaches. For instance, Fast-Flux Service Networks is one of emerging attack technologies, which is used to invade the system through combining the RR-DNS technology (Round Robin DNS) of DNS. Fast-Flux can protect malicious websites by keeping changing the IP address of the Mothership. In most cases, naïve users’ computers are usually the attack targets so the damage is getting worse with each passing day. Therefore, this study uses FFSN characterization and original features as detection patterns to construct a detection system. The data from ATLAS and ALEXA are tested to evaluate the detection rate and accuracy of the proposed system. Finally, through the analysis of the detection effectiveness after features mapping, the best solution can be found as the future detection pattern.
|
author2 |
Tung-ming Koo |
author_facet |
Tung-ming Koo Tsung-en Huang 黃宗恩 |
author |
Tsung-en Huang 黃宗恩 |
spellingShingle |
Tsung-en Huang 黃宗恩 Fast-Flux Service Networks (FFSN) Detection Based on DNS MX Record |
author_sort |
Tsung-en Huang |
title |
Fast-Flux Service Networks (FFSN) Detection Based on DNS MX Record |
title_short |
Fast-Flux Service Networks (FFSN) Detection Based on DNS MX Record |
title_full |
Fast-Flux Service Networks (FFSN) Detection Based on DNS MX Record |
title_fullStr |
Fast-Flux Service Networks (FFSN) Detection Based on DNS MX Record |
title_full_unstemmed |
Fast-Flux Service Networks (FFSN) Detection Based on DNS MX Record |
title_sort |
fast-flux service networks (ffsn) detection based on dns mx record |
publishDate |
2012 |
url |
http://ndltd.ncl.edu.tw/handle/67451821200819479758 |
work_keys_str_mv |
AT tsungenhuang fastfluxservicenetworksffsndetectionbasedondnsmxrecord AT huángzōngēn fastfluxservicenetworksffsndetectionbasedondnsmxrecord AT tsungenhuang yǐwǎngyùmíngchēngfúwùzhīyóujiànjiāohuànjìlùwèijīchǔzhēncèdòngtàièyìyùmíngfúwùwǎnglù AT huángzōngēn yǐwǎngyùmíngchēngfúwùzhīyóujiànjiāohuànjìlùwèijīchǔzhēncèdòngtàièyìyùmíngfúwùwǎnglù |
_version_ |
1718070277961678848 |