Journal of Information Processing
Online ISSN : 1882-6652
ISSN-L : 1882-6652
Detection and Filtering System for DNS Water Torture Attacks Relying Only on Domain Name Information
Takuro YoshidaKento KawakamiRyotaro KobayashiMasahiko KatoMasayuki OkadaHiroyuki Kishimoto
著者情報
ジャーナル フリー

2017 年 25 巻 p. 854-865

詳細
抄録

Water torture attacks are a recently emerging type of Distributed Denial-of-Service (DDoS) attack on Domain Name System (DNS) servers. They generate a multitude of malicious queries with randomized, unique subdomains. This paper proposes a detection method and a filtering system for water torture attacks. The former is an enhancement of our previous effort so as to achieve packet-by-packet, on-the-fly processing, and the latter is an application of our current method mainly for defending recursive servers. Our proposed method detects malicious queries by analyzing their subdomains with a naïve Bayes classifier. Considering large-scale applications, we focus on achieving high throughput as well as high accuracy. Experimental results indicate that our method can detect attacks with 98.16% accuracy and only a 1.55% false positive rate, and that our system can process up to 7.44Mpps of traffic.

著者関連情報
© 2017 by the Information Processing Society of Japan
前の記事 次の記事
feedback
Top