Real time DNS traffic profiling enhanced detection design for national level network

Muhammad Salahuddien Manggalanny, Kalamullah Ramli

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

2 Citations (Scopus)

Abstract

A recent study shows, an investigation of Advanced Persistent Threat (APT) activity can be done effectively through malicious DNS traffic analysis. But, most of the experiments are conducted in a limited, simulated environment e.g. small campus network. Since APT is very dynamic and to address traffic grows, a light weight computation architecture is then needed to profile suspected activity in near real time. In this study, we proposed an enhanced design to detect malicious DNS traffic for high speed, large scale, national level, near real time network. This experiment combines available open source solution tools in order to gain real time, better accuracy of anomaly recognition and faster detection.

Original languageEnglish
Title of host publication2017 International Seminar on Intelligent Technology and Its Application
Subtitle of host publicationStrengthening the Link Between University Research and Industry to Support ASEAN Energy Sector, ISITIA 2017 - Proceeding
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages11-15
Number of pages5
ISBN (Electronic)9781538627068
DOIs
Publication statusPublished - 28 Nov 2017
Event18th International Seminar on Intelligent Technology and Its Application, ISITIA 2017 - Surabaya, Indonesia
Duration: 28 Aug 201729 Aug 2017

Publication series

Name2017 International Seminar on Intelligent Technology and Its Application: Strengthening the Link Between University Research and Industry to Support ASEAN Energy Sector, ISITIA 2017 - Proceeding
Volume2017-January

Conference

Conference18th International Seminar on Intelligent Technology and Its Application, ISITIA 2017
Country/TerritoryIndonesia
CitySurabaya
Period28/08/1729/08/17

Keywords

  • Anomaly detection
  • DNS
  • Traffic profiling

Fingerprint

Dive into the research topics of 'Real time DNS traffic profiling enhanced detection design for national level network'. Together they form a unique fingerprint.

Cite this