کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
452957 694674 2013 13 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Genetic-based real-time fast-flux service networks detection
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
پیش نمایش صفحه اول مقاله
Genetic-based real-time fast-flux service networks detection
چکیده انگلیسی

A new DNS technique called Fast-Flux Service Network (FFSN) has been employed by bot herders to hide malicious activities and extend the lifetime of malicious root servers. Although various methods have been proposed for detecting FFSNs, these mechanisms have low detection accuracy and protracted detection time. This study presents a novel detection scheme, designated as the Genetic-based ReAl-time DEtection (GRADE) system, to identify FFSNs in real time. GRADE differentiates between FFSNs and benign services by employing two new characteristics: the entropy of domains of preceding nodes for all A records and the standard deviation of round trip time to all A records. By applying genetic algorithms, GRADE is able to find the best strategy to detect current FFSN trends. Empirical results show GRADE has very high detection accuracy (∼98%) and gives results within a few seconds. It provides considerable improvement over existing reference schemes such Flux-Score [8], SSFD [13], and FFSD [14].

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Computer Networks - Volume 57, Issue 2, 4 February 2013, Pages 501–513
نویسندگان
, , ,