首页 | 本学科首页   官方微博 | 高级检索  
     

基于命名及解析行为特征的异常域名检测方法
引用本文:周勇林,由林麟,张永铮.基于命名及解析行为特征的异常域名检测方法[J].计算机工程与应用,2011,47(20):50-52.
作者姓名:周勇林  由林麟  张永铮
作者单位:1. 国家计算机网络应急技术处理协调中心,北京,100029
2. 中国科学院计算技术研究所,北京100190;哈尔滨工业大学软件学院,哈尔滨150001
3. 中国科学院计算技术研究所,北京,100190
基金项目:国家自然科学基金,国家高技术研究发展计划(863)
摘    要:设计了DNS解析统计向量和检测特征向量,提出了一种基于命名及解析行为特征的异常域名检测方法,通过应用真实DNS解析数据的实验验证了该方法的有效性和可行性。实验表明,该方法较现有方法能够发现更多的异常域名,且具有较低的误报率。该方法是对现有方法检测能力的补充和提高,为僵尸网络等安全事件的检测与控制提供有效的信息支持和技术手段。

关 键 词:网络安全  异常域名  检测  解析行为
修稿时间: 

Anomaly domain name detection method based on characteristics of name and resolution behavior
ZHOU Yonglin,YOU Linlin,ZHANG Yongzheng.Anomaly domain name detection method based on characteristics of name and resolution behavior[J].Computer Engineering and Applications,2011,47(20):50-52.
Authors:ZHOU Yonglin  YOU Linlin  ZHANG Yongzheng
Affiliation:1.National Computer Network Emergency Response Technical Team/Coordination Center of China,Beijing 100029,China 2.Institute of Computing Technology,Chinese Academy of Sciences,Beijing 100190,China 3.School of Software,Harbin Institute of Technology,Harbin 150001,China
Abstract:A statistical vector of domain name resolution and a characteristic vector of detection are designed in this paper. An anomaly domain name detection method based on the characteristics of name and resolution behavior is proposed.An experiment using the real resolution traffic of Domain Name System(DNS) is designed to validate the effectiveness and feasibility of this method.Experimental results show that compared with the existing methods,this method can find more anomaly domain names and has a relatively lower false of the existing methods, and moreover provides ty events such as botnets. positive rate.This method can be used to complement and enhance the ability effective information and technical support for detection and control of security events such as botnets.
Keywords:network security  anomaly Domain Name System(DNS)  detection  resolution behavior
本文献已被 CNKI 维普 万方数据 等数据库收录!
点击此处可从《计算机工程与应用》浏览原始摘要信息
点击此处可从《计算机工程与应用》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号