Recursive DNS plays a pivotal role in safeguarding the security and reliability of users’ access to diverse Internet services. A malfunctioning recursive DNS may impair users’ online experience and pose a grave threat to the security and integrity of the domain name system. Nevertheless, the huge scale and scattered distribution characteristics of recursive DNS make the measurement of abnormal recursive DNS very difficult. In this study, we will take an in-depth look at how top-level domain resolution logs can be used to evaluate and dissect large-scale recursive DNS query patterns. Precisely, we adopt a passive measurement approach, analyzing a massive dataset comprising 1.3 billion resolution logs gathered from. CN top-level domain name servers and also encompassing 110,599 source IPs. Leveraging our profound domain knowledge, we have identified and extracted 12 key features of aberrant recursive DNS query behaviors. Furthermore, we developed a t-SNE-based density clustering model, which has successfully pinpointed 1,417 anomalous recursive DNS servers. Finally, based on our domain expertise and authoritative experts’ insights, we classify these abnormal recursive DNS query behaviors into four categories. Through an in-depth analysis of the intrinsic driving mechanisms of four abnormal behaviors, we provide a comprehensive foundation for recursive DNS safety governance and thus enhance users’ online security.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Large-Scale Study of Abnormal Recursive DNS

  • Anlei Hu,
  • Liangyi Gong,
  • Jieling Xie,
  • Yufu Li,
  • Gaogang Xie

摘要

Recursive DNS plays a pivotal role in safeguarding the security and reliability of users’ access to diverse Internet services. A malfunctioning recursive DNS may impair users’ online experience and pose a grave threat to the security and integrity of the domain name system. Nevertheless, the huge scale and scattered distribution characteristics of recursive DNS make the measurement of abnormal recursive DNS very difficult. In this study, we will take an in-depth look at how top-level domain resolution logs can be used to evaluate and dissect large-scale recursive DNS query patterns. Precisely, we adopt a passive measurement approach, analyzing a massive dataset comprising 1.3 billion resolution logs gathered from. CN top-level domain name servers and also encompassing 110,599 source IPs. Leveraging our profound domain knowledge, we have identified and extracted 12 key features of aberrant recursive DNS query behaviors. Furthermore, we developed a t-SNE-based density clustering model, which has successfully pinpointed 1,417 anomalous recursive DNS servers. Finally, based on our domain expertise and authoritative experts’ insights, we classify these abnormal recursive DNS query behaviors into four categories. Through an in-depth analysis of the intrinsic driving mechanisms of four abnormal behaviors, we provide a comprehensive foundation for recursive DNS safety governance and thus enhance users’ online security.