...
【24h】

DNS Traffic Analysis Platform with Hadoop Framework

机译:具有Hadoop框架的DNS流量分析平台

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Recently, cyber threats have rapidly grown in regarding to the large scale of botnets as well as the financial damages from the threat. Botnet is organized numerous bot PCs that are compromised and allow to run criminal software by unauthorized access. Detecting each bot PC represents an important issue in the cyber security, and various approach are contributed to develop detection algorithms. DNS traffic analysis is. one of the detection approaches and aims at characterizing malwares' footprints. While bot PCs tend to query some distinctive domain names, the analysis of the characteristics enables to detect botnets. This paper hereby introduces a suitable infrastructure for DNS traffic analysis in which various DNS analysis methodologies are adoptable. The paper also proposes the schemes not only for DNS traffic analysis, but also for the analysis methodologies of other incidents, in order to develop a collaborative analysis method across multiple cyber threats.
机译:最近,关于大规模僵尸网络以及威胁造成的经济损失,网络威胁迅速增长。僵尸网络组织了许多被破坏的僵尸计算机,它们被未经授权的访问允许运行犯罪软件。检测每台机器人PC代表了网络安全中的一个重要问题,并且为开发检测算法做出了各种贡献。是DNS流量分析。一种检测方法,旨在表征恶意软件的足迹。虽然僵尸PC倾向于查询一些独特的域名,但是对特征的分析可以检测到僵尸网络。本文在此介绍一种适用于DNS流量分析的基础结构,其中可以采用各种DNS分析方法。本文还提出了不仅用于DNS流量分析的方案,而且还针对其他事件的分析方法提出了方案,以便开发一种跨多种网络威胁的协作分析方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号