Genetic-based Real-time Fast-Flux Service Networks Detection

被引:19
|
作者
Lin, Hui-Tang [1 ,2 ]
Lin, Ying-You [2 ]
Chiang, Jui-Wei [2 ]
机构
[1] Natl Cheng Kung Univ, Dept Elect Engn, Tainan 70101, Taiwan
[2] Natl Cheng Kung Univ, Inst Comp & Commun Engn, Tainan 70101, Taiwan
关键词
Network security; Fast-flux service networks; Botnets; ALGORITHMS;
D O I
10.1016/j.comnet.2012.07.017
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
A new DNS technique called Fast-Flux Service Network (FFSN) has been employed by bot herders to hide malicious activities and extend the lifetime of malicious root servers. Although various methods have been proposed for detecting FFSNs, these mechanisms have low detection accuracy and protracted detection time. This study presents a novel detection scheme, designated as the Genetic-based ReAl-time DEtection (GRADE) system, to identify FFSNs in real time. GRADE differentiates between FFSNs and benign services by employing two new characteristics: the entropy of domains of preceding nodes for all A records and the standard deviation of round trip time to all A records. By applying genetic algorithms, GRADE is able to find the best strategy to detect current FFSN trends. Empirical results show GRADE has very high detection accuracy (similar to 98%) and gives results within a few seconds. It provides considerable improvement over existing reference schemes such Flux-Score [9], FFBD [13] and SSFD [14]. (c) 2012 Elsevier B.V. All rights reserved.
引用
收藏
页码:501 / 513
页数:13
相关论文
共 50 条
  • [21] FAST HEURISTIC SCHEDULING BASED ON NEURAL NETWORKS FOR REAL-TIME SYSTEMS
    THAWONMAS, R
    CHAKRABORTY, G
    SHIRATORI, N
    REAL-TIME SYSTEMS, 1995, 9 (03) : 289 - 304
  • [22] Fast heuristic scheduling based on neural networks for real-time systems
    Thawonmas, Ruck, 1600, Kluwer Academic Publishers, Dordrecht, Netherlands (09):
  • [23] Fast-flux Attack Network Identification Based on Agent Lifespan
    Yu, Sheng
    Zhou, Shijie
    Wang, Sha
    2010 IEEE INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, NETWORKING AND INFORMATION SECURITY (WCNIS), VOL 1, 2010, : 658 - 662
  • [24] A CORBA-based real-time stream service for ATM networks
    Sapkota, BS
    Pung, HK
    Ngoh, LH
    Wong, L
    IEEE INTERNATIONAL CONFERENCE ON MULTIMEDIA COMPUTING AND SYSTEMS '97, PROCEEDINGS, 1997, : 648 - 649
  • [25] Detecting Web-Based Botnets with Fast-Flux Domains
    Chen, C.-M. (cchen@mail.nsysu.edu.tw), 1600, Springer Science and Business Media Deutschland GmbH (21):
  • [26] Real-Time Measurement of Cycloduction Movement Based on Fast Ellipse Detection
    Sakashita, Yuusuke
    Fujiyoshi, Hironobu
    Hirata, Yutaka
    Takamaru, Hisanori
    Fukaya, Naoki
    ELECTRONICS AND COMMUNICATIONS IN JAPAN, 2009, 92 (11) : 9 - 18
  • [27] Real-time Detection of Electrocardiograph Peaks: A Genetic Algorithm based Approach
    Jain, Shweta
    Kumar, Anil
    Bajaj, Varun
    2017 4TH INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING AND INTEGRATED NETWORKS (SPIN), 2017, : 262 - 266
  • [28] Fast Real-Time Scheduling for Ethernet-based Train Control Networks
    Yu, Qinghan
    Wang, Tian
    Zhao, Xibin
    Wan, Hai
    Gao, Yue
    Lu, Chenyang
    Gu, Ming
    2018 IEEE INT CONF ON PARALLEL & DISTRIBUTED PROCESSING WITH APPLICATIONS, UBIQUITOUS COMPUTING & COMMUNICATIONS, BIG DATA & CLOUD COMPUTING, SOCIAL COMPUTING & NETWORKING, SUSTAINABLE COMPUTING & COMMUNICATIONS, 2018, : 533 - 540
  • [29] Real-Time Detection and Localization of Denial-of-Service Attacks in Heterogeneous Vehicular Networks
    Dey, Meenu Rani
    Patra, Moumita
    Mishra, Prabhat
    PROCEEDINGS OF THE 2021 DESIGN, AUTOMATION & TEST IN EUROPE CONFERENCE & EXHIBITION (DATE 2021), 2021, : 1434 - 1439
  • [30] Providing Real-Time Service in CDMA Wireless Networks
    Maode Ma
    Qichao Zhu
    Wireless Personal Communications, 2007, 41 : 551 - 562