TY - GEN
T1 - Real time DNS traffic profiling enhanced detection design for national level network
AU - Manggalanny, Muhammad Salahuddien
AU - Ramli, Kalamullah
N1 - Publisher Copyright:
© 2017 IEEE.
PY - 2017/11/28
Y1 - 2017/11/28
N2 - A recent study shows, an investigation of Advanced Persistent Threat (APT) activity can be done effectively through malicious DNS traffic analysis. But, most of the experiments are conducted in a limited, simulated environment e.g. small campus network. Since APT is very dynamic and to address traffic grows, a light weight computation architecture is then needed to profile suspected activity in near real time. In this study, we proposed an enhanced design to detect malicious DNS traffic for high speed, large scale, national level, near real time network. This experiment combines available open source solution tools in order to gain real time, better accuracy of anomaly recognition and faster detection.
AB - A recent study shows, an investigation of Advanced Persistent Threat (APT) activity can be done effectively through malicious DNS traffic analysis. But, most of the experiments are conducted in a limited, simulated environment e.g. small campus network. Since APT is very dynamic and to address traffic grows, a light weight computation architecture is then needed to profile suspected activity in near real time. In this study, we proposed an enhanced design to detect malicious DNS traffic for high speed, large scale, national level, near real time network. This experiment combines available open source solution tools in order to gain real time, better accuracy of anomaly recognition and faster detection.
KW - Anomaly detection
KW - DNS
KW - Traffic profiling
UR - http://www.scopus.com/inward/record.url?scp=85043533799&partnerID=8YFLogxK
U2 - 10.1109/ISITIA.2017.8124046
DO - 10.1109/ISITIA.2017.8124046
M3 - Conference contribution
AN - SCOPUS:85043533799
T3 - 2017 International Seminar on Intelligent Technology and Its Application: Strengthening the Link Between University Research and Industry to Support ASEAN Energy Sector, ISITIA 2017 - Proceeding
SP - 11
EP - 15
BT - 2017 International Seminar on Intelligent Technology and Its Application
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 18th International Seminar on Intelligent Technology and Its Application, ISITIA 2017
Y2 - 28 August 2017 through 29 August 2017
ER -