首页 | 本学科首页   官方微博 | 高级检索  
     

基于日志信息的DNS查询异常检测算法
引用本文:吉星,黄韬,鄂新华,孙礼.基于日志信息的DNS查询异常检测算法[J].北京邮电大学学报,2018,41(6):83-89.
作者姓名:吉星  黄韬  鄂新华  孙礼
作者单位:1. 北京邮电大学 信息与通信工程学院, 北京 100876;
2. 北京工业大学 北京未来网络科技高精尖创新中心, 北京 100124
基金项目:国家重点基础研究发展计划(973计划);国家自然科学基金;中国工程院重大咨询研究项目
摘    要:针对域名系统(DNS)中存在异常查询的问题,提出了一种基于日志信息的DNS查询异常检测算法,以检测异常的互联网协议地址(IP).通过分析DNS正常与异常请求行为的区别,提取了DNS日志中多个维度的信息来表征源IP;其次,利用降维处理将数据映射到三维空间,以便直观地可视化呈现和快速地进行数据分析;最后,利用聚类分析和计算各源IP的可信度,检测出异常的源IP.实验结果表明,所提算法不但能直观观察到多维数据集中的关联特性,而且能从全局和局部2个层面识别网络中异常的源IP.

关 键 词:域名系统查询  降维  聚类分析  异常检测  
收稿时间:2018-01-09

A DNS Query Anomaly Detection Algorithm Based on Log Information
JI Xing,HUANG Tao,E Xin-hua,SUN Li.A DNS Query Anomaly Detection Algorithm Based on Log Information[J].Journal of Beijing University of Posts and Telecommunications,2018,41(6):83-89.
Authors:JI Xing  HUANG Tao  E Xin-hua  SUN Li
Affiliation:1. School of Information and Communication Engineering, Beijing University of Posts and Telecommunications, Beijing 100876, China;
2. Beijing Advanced Innovation Center for Future Internet Technology, Beijing University of Technology, Beijing 100124, China
Abstract:Point at the anomaly queries existing in domain name system (DNS), an anomaly detection algorithm based on DNS query logs is proposed to detect suspicious and abnormal internet protocol addresses (IP). First, multiple dimensions of information in the DNS logs are extracted to characterize the source IPs after analyzing the difference between normal DNS query behaviors and the abnormal ones. Secondly, the datasets are mapped to a three-dimensional space through dimensionality reduction, which is beneficial for intuitive visualization and rapid data analysis. Finally, clustering the source IPs and calculating the credibility of them to identify the abnormal ones. The experiment results show that this algorithm can not only observe the correlation characteristics of multi-dimensional datasets directly, but also identify the abnormal source IPs in the global and local aspects.
Keywords:domain name system query  dimensionality reduction  cluster analysis  anomaly detection  
本文献已被 万方数据 等数据库收录!
点击此处可从《北京邮电大学学报》浏览原始摘要信息
点击此处可从《北京邮电大学学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号