Sciweavers

DIMVA
2007

Passive Monitoring of DNS Anomalies

13 years 6 months ago
Passive Monitoring of DNS Anomalies
We collected DNS responses at the University of Auckland Internet gateway in an SQL database, and analyzed them to detect unusual behaviour. Our DNS response data have included typo squatter domains, fast flux domains and domains being (ab)used by spammers. We observe that current attempts to reduce spam have greatly increased the number of A records being resolved. We also observe that the data locality of DNS requests diminishes because of domains advertised in spam.
Bojan Zdrnja, Nevil Brownlee, Duane Wessels
Added 29 Oct 2010
Updated 29 Oct 2010
Type Conference
Year 2007
Where DIMVA
Authors Bojan Zdrnja, Nevil Brownlee, Duane Wessels
Comments (0)