{"title":"Statistical study of unusual DNS query traffic","authors":"D. Romaņa, Y. Musashi, H. Nagatomi, K. Sugitani","doi":"10.1109/ISCIT.2007.4392087","DOIUrl":null,"url":null,"abstract":"We statistically investigated on the unusual big DNS resolution traffic toward the top domain DNS server from a university local campus network in April 11th, 2006. The following results are obtained: (1) In April 11th, the DNS query traffic includes a lot of fully qualified domain names (FQDNs) of several specific Web sites as name resolution keywords. (2) Also, the DNS query traffic includes a plenty of source IP addresses of PC clients. Usually, we can observe the source IP addresses of E-mail and/or Web servers in the usual DNS query traffic, mainly. From this point, it can be concluded that the PC clients are probably infected with bot worms (BWs) and they have tried to crash the top domain DNS server.","PeriodicalId":331439,"journal":{"name":"2007 International Symposium on Communications and Information Technologies","volume":"301 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2007-12-04","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2007 International Symposium on Communications and Information Technologies","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ISCIT.2007.4392087","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3
Abstract
We statistically investigated on the unusual big DNS resolution traffic toward the top domain DNS server from a university local campus network in April 11th, 2006. The following results are obtained: (1) In April 11th, the DNS query traffic includes a lot of fully qualified domain names (FQDNs) of several specific Web sites as name resolution keywords. (2) Also, the DNS query traffic includes a plenty of source IP addresses of PC clients. Usually, we can observe the source IP addresses of E-mail and/or Web servers in the usual DNS query traffic, mainly. From this point, it can be concluded that the PC clients are probably infected with bot worms (BWs) and they have tried to crash the top domain DNS server.