2019
DOI: 10.1109/access.2019.2924633
|View full text |Cite
|
Sign up to set email alerts
|

DNS-ADVP: A Machine Learning Anomaly Detection and Visual Platform to Protect Top-Level Domain Name Servers Against DDoS Attacks

Abstract: DNS DDoS attacks may severely affect the operation of computer networks, prompting the need for methods able to timely detect them, and then to apply mitigation countermeasures. Visual models have been used to detect an ongoing DDoS attack, but often demand continuous attention from IT staff. However, machine learning techniques could complement a visual model with further information and with on-time alerts that could help IT officers give attention only when an attack is in progress at its very early stage. … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
16
0

Year Published

2020
2020
2022
2022

Publication Types

Select...
4
2

Relationship

1
5

Authors

Journals

citations
Cited by 20 publications
(16 citation statements)
references
References 15 publications
0
16
0
Order By: Relevance
“…Developing detection methods for cyber security can be divided broadly into two main approaches: signature-based detection [21]- [23] and anomaly-based detection [7], [15], [24]- [27]. To identify malicious domains, detection methods typically use DNS data, as considered in this paper.…”
Section: B Related Workmentioning
confidence: 99%
See 4 more Smart Citations
“…Developing detection methods for cyber security can be divided broadly into two main approaches: signature-based detection [21]- [23] and anomaly-based detection [7], [15], [24]- [27]. To identify malicious domains, detection methods typically use DNS data, as considered in this paper.…”
Section: B Related Workmentioning
confidence: 99%
“…However, due to caching at the recursive resolver level, not all queries will be visible to that server. The DNS-ADVP platform [7] analyzes passive DNS records from an Authoritative DNS server to identify DDoS (Distributed Denial of Service) attacks against Top-Level domains. The Kopis system [12] passively monitors DNS traffic at the upper levels of the DNS hierarchy (Authoritative servers and TLDs) to detect malware domains using the global visibility obtained by monitoring network traffic at the upper DNS hierarchy without relying on monitoring traffic from local recursive DNS servers.…”
Section: ) Dns Data Collectionmentioning
confidence: 99%
See 3 more Smart Citations