کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
826392 907923 2014 7 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Fast Flux Watch: A mechanism for online detection of fast flux networks
ترجمه فارسی عنوان
شارژ سریع شارژ: یک مکانیزم برای تشخیص آنلاین شبکه های شار سریع
موضوعات مرتبط
مهندسی و علوم پایه شیمی شیمی (عمومی)
چکیده انگلیسی

Fast flux networks represent a special type of botnets that are used to provide highly available web services to a backend server, which usually hosts malicious content. Detection of fast flux networks continues to be a challenging issue because of the similar behavior between these networks and other legitimate infrastructures, such as CDNs and server farms. This paper proposes Fast Flux Watch (FF-Watch), a mechanism for online detection of fast flux agents. FF-Watch is envisioned to exist as a software agent at leaf routers that connect stub networks to the Internet. The core mechanism of FF-Watch is based on the inherent feature of fast flux networks: flux agents within stub networks take the role of relaying client requests to point-of-sale websites of spam campaigns. The main idea of FF-Watch is to correlate incoming TCP connection requests to flux agents within a stub network with outgoing TCP connection requests from the same agents to the point-of-sale website. Theoretical and traffic trace driven analysis shows that the proposed mechanism can be utilized to efficiently detect fast flux agents within a stub network.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Journal of Advanced Research - Volume 5, Issue 4, July 2014, Pages 473–479
نویسندگان
, ,