Passive Monitoring of DNS Anomalies

  • Authors:
  • Bojan Zdrnja;Nevil Brownlee;Duane Wessels

  • Affiliations:
  • University of Auckland, New Zealand;University of Auckland, New Zealand;The Measurement Factory, Inc.,

  • Venue:
  • DIMVA '07 Proceedings of the 4th international conference on Detection of Intrusions and Malware, and Vulnerability Assessment
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

We collected DNS responses at the University of Auckland Internet gateway in an SQL database, and analyzed them to detect unusual behaviour. Our DNS response data have included typo squatter domains, fast flux domains and domains being (ab)used by spammers. We observe that current attempts to reduce spam have greatly increased the number of A records being resolved. We also observe that the data locality of DNS requests diminishes because of domains advertised in spam.