Large Scale DNS Traffic Analysis of Malicious Internet Activity with a Focus on Evaluating the Response Time of Blocking Phishing Sites

Saved in:
Bibliographic Details
Title: Large Scale DNS Traffic Analysis of Malicious Internet Activity with a Focus on Evaluating the Response Time of Blocking Phishing Sites
Authors: Spring, Jonathan M.
Summary: This thesis explores four research areas that are examined using DNS traffic analysis. The tools used for this analysis are presented first. The four topics examined are domain mapping, response time of anti-phishing block lists to find the phishing sites, automated identification of malicious fast-flux hosting domains, and identification of distributed denial of service attacks. The first three approaches yielded successful results, and the fourth yields primarily negative lessons for using DNS traffic analysis in such a scenario. Much of the analysis concerns the anti-phishing response time, which has yielded tentative results. It is found that there is significant overlap between the automatically identified fast-flux sites and those sites on the block list. It appears that domains were being put onto the list approximately 11 hours after becoming active, in the median case, which is very nearly the median lifetime of a phishing site. More recently collected data indicates that this result is extremely difficult to verify. While further work is necessary to verify these claims, the initial indication is that finding and listing phishing sites is the bottleneck in propagating data to protect consumers from malicious phishing sites.
URL: http://d-scholarship.pitt.edu/7721/1/JMSpring_PittThesis2010.pdf
Database: OpenDissertations
FullText Text:
  Availability: 0
Header DbId: ddu
DbLabel: OpenDissertations
An: ddu.oai.d.scholarship.pitt.edu.7721
AccessLevel: 6
PubType: Dissertation/ Thesis
PubTypeId: dissertation
PreciseRelevancyScore: 0
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: Large Scale DNS Traffic Analysis of Malicious Internet Activity with a Focus on Evaluating the Response Time of Blocking Phishing Sites
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Spring%2C+Jonathan+M%2E%22">Spring, Jonathan M.</searchLink>
– Name: Abstract
  Label: Summary
  Group: Ab
  Data: This thesis explores four research areas that are examined using DNS traffic analysis. The tools used for this analysis are presented first. The four topics examined are domain mapping, response time of anti-phishing block lists to find the phishing sites, automated identification of malicious fast-flux hosting domains, and identification of distributed denial of service attacks. The first three approaches yielded successful results, and the fourth yields primarily negative lessons for using DNS traffic analysis in such a scenario. Much of the analysis concerns the anti-phishing response time, which has yielded tentative results. It is found that there is significant overlap between the automatically identified fast-flux sites and those sites on the block list. It appears that domains were being put onto the list approximately 11 hours after becoming active, in the median case, which is very nearly the median lifetime of a phishing site. More recently collected data indicates that this result is extremely difficult to verify. While further work is necessary to verify these claims, the initial indication is that finding and listing phishing sites is the bottleneck in propagating data to protect consumers from malicious phishing sites.
– Name: URL
  Label: URL
  Group: URL
  Data: <link linkTarget="URL" linkTerm="http://d-scholarship.pitt.edu/7721/1/JMSpring_PittThesis2010.pdf" linkWindow="_blank">http://d-scholarship.pitt.edu/7721/1/JMSpring_PittThesis2010.pdf</link>
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=ddu&AN=ddu.oai.d.scholarship.pitt.edu.7721
RecordInfo BibRecord:
  BibEntity:
    Languages:
      – Code: eng
        Text: English
    Titles:
      – TitleFull: Large Scale DNS Traffic Analysis of Malicious Internet Activity with a Focus on Evaluating the Response Time of Blocking Phishing Sites
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Spring, Jonathan M.
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 12
              M: 05
              Type: published
              Y: 2010
ResultId 1