Caiyun Huang, Peng Zhang, Yong Sun, Yujia Zhu, Yang Liu
{"title":"基于多协议交叉验证的DNS劫持自反馈检测系统","authors":"Caiyun Huang, Peng Zhang, Yong Sun, Yujia Zhu, Yang Liu","doi":"10.1109/ICT.2019.8798832","DOIUrl":null,"url":null,"abstract":"With the rapid growth of the Internet, concerns about the security of Domain Name System (DNS) have become prominent. DNS Hijacking is a typical threat which manipulates DNS resource records (RRs) to make users obtain wrong website server IPs through Cache Poisoning or Man-in-the-middle attack. In this paper, we propose a Self-Feedback Detection System (SFDS) deployed at Local Area Network (LAN) Gateway to protect users from visiting the wrong websites. SFDS: (i)finds the incorrect (Domain, IP) tuples in real-time to provide a correct (Domain, IP) tuple list for users, (ii)utilizes a multi-protocol cross validation method to verify suspicious (Domain, IP) tuples, (iii) applies self-feedback mechanism to calculate the correctness probabilities of (Domain, IP) tuples iteratively. We show that in real circumstance for two weeks, SFDS can find almost 1300 correct (Domain, IP) tuples for one domain on average in one day. And SFDS is effective with accuracy approximately 100% by our experiments.","PeriodicalId":127412,"journal":{"name":"2019 26th International Conference on Telecommunications (ICT)","volume":"84 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-04-08","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":"{\"title\":\"SFDS: A Self-Feedback Detection System for DNS Hijacking Based on Multi-Protocol Cross Validation\",\"authors\":\"Caiyun Huang, Peng Zhang, Yong Sun, Yujia Zhu, Yang Liu\",\"doi\":\"10.1109/ICT.2019.8798832\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"With the rapid growth of the Internet, concerns about the security of Domain Name System (DNS) have become prominent. DNS Hijacking is a typical threat which manipulates DNS resource records (RRs) to make users obtain wrong website server IPs through Cache Poisoning or Man-in-the-middle attack. In this paper, we propose a Self-Feedback Detection System (SFDS) deployed at Local Area Network (LAN) Gateway to protect users from visiting the wrong websites. SFDS: (i)finds the incorrect (Domain, IP) tuples in real-time to provide a correct (Domain, IP) tuple list for users, (ii)utilizes a multi-protocol cross validation method to verify suspicious (Domain, IP) tuples, (iii) applies self-feedback mechanism to calculate the correctness probabilities of (Domain, IP) tuples iteratively. We show that in real circumstance for two weeks, SFDS can find almost 1300 correct (Domain, IP) tuples for one domain on average in one day. And SFDS is effective with accuracy approximately 100% by our experiments.\",\"PeriodicalId\":127412,\"journal\":{\"name\":\"2019 26th International Conference on Telecommunications (ICT)\",\"volume\":\"84 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2019-04-08\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"2\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2019 26th International Conference on Telecommunications (ICT)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICT.2019.8798832\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2019 26th International Conference on Telecommunications (ICT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICT.2019.8798832","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
SFDS: A Self-Feedback Detection System for DNS Hijacking Based on Multi-Protocol Cross Validation
With the rapid growth of the Internet, concerns about the security of Domain Name System (DNS) have become prominent. DNS Hijacking is a typical threat which manipulates DNS resource records (RRs) to make users obtain wrong website server IPs through Cache Poisoning or Man-in-the-middle attack. In this paper, we propose a Self-Feedback Detection System (SFDS) deployed at Local Area Network (LAN) Gateway to protect users from visiting the wrong websites. SFDS: (i)finds the incorrect (Domain, IP) tuples in real-time to provide a correct (Domain, IP) tuple list for users, (ii)utilizes a multi-protocol cross validation method to verify suspicious (Domain, IP) tuples, (iii) applies self-feedback mechanism to calculate the correctness probabilities of (Domain, IP) tuples iteratively. We show that in real circumstance for two weeks, SFDS can find almost 1300 correct (Domain, IP) tuples for one domain on average in one day. And SFDS is effective with accuracy approximately 100% by our experiments.