Combination of DNS traffic analysis: A design to enhance APT detection

Muhammad Salahuddien Manggalanny, Kalamullah Ramli

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

An activity of Advanced Persistent Threat (APT) is very dynamic. A single detection method will be ineffective. New modus and techniques are being developed rapidly and overcome the effort to acknowledge it. This design proposed a new approach through a combination of previous successful detection method based on DNS traffic analysis altogether, to address today's APT challenges. A preliminary experiment shows promising and better accuracy of APT recognition and faster response.

Original languageEnglish
Title of host publicationProceeding - 2017 3rd International Conference on Science and Technology-Computer, ICST 2017
EditorsPutu Sugiartawan, Khabib Mustofa, Sunu Wibirama, Faizal Makhrus, Lasmedi Afuan, Nurul Hidayat, Hamdani, Emi Setyaningsih, Rahmad Hidayat
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages171-175
Number of pages5
ISBN (Electronic)9781538618745
DOIs
Publication statusPublished - 16 Aug 2017
Event3rd International Conference on Science and Technology-Computer, ICST 2017 - Yogyakarta, Indonesia
Duration: 11 Jul 201712 Jul 2017

Publication series

NameProceeding - 2017 3rd International Conference on Science and Technology-Computer, ICST 2017

Conference

Conference3rd International Conference on Science and Technology-Computer, ICST 2017
Country/TerritoryIndonesia
CityYogyakarta
Period11/07/1712/07/17

Keywords

  • APT
  • DNS
  • anomaly detection
  • traffic analysis

Fingerprint

Dive into the research topics of 'Combination of DNS traffic analysis: A design to enhance APT detection'. Together they form a unique fingerprint.

Cite this