Title
Automatic Detection Of Dns Manipulations
Abstract
The DNS is a fundamental service that has been repeatedly attacked and abused. DNS manipulation is a prominent case: Recursive DNS resolvers are deployed to explicitly return manipulated answers to users' queries. While DNS manipulation is used for legitimate reasons too (e.g., parental control), rogue DNS resolvers support malicious activities, such as malware and viruses, exposing users to phishing and content injection.We introduce REMeDy, a system that assists operators to identify the use of rogue DNS resolvers in their networks. REMeDy is a completely automatic and parameter-free system that evaluates the consistency of responses across the resolvers active in the network. It operates by passively analyzing DNS traffic and, as such, requires no active probing of third-party servers. REMeDy is able to detect resolvers that manipulate answers, including resolvers that affect unpopular domains.We validate REMeDy using large-scale DNS traces collected in ISP networks where more than 100 resolvers are regularly used by customers. REMeDy automatically identifies regular resolvers, and pinpoint manipulated responses. Among those, we identify both legitimate services that offer additional protection to clients, and resolvers under the control of malwares that steer traffic with likely malicious goals.
Year
DOI
Venue
2017
10.1109/BigData.2017.8258415
2017 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA)
DocType
ISSN
Citations 
Conference
2639-1589
0
PageRank 
References 
Authors
0.34
0
4
Name
Order
Citations
PageRank
Martino Trevisan17816.10
Idilio Drago229827.35
Marco Mellia32748204.65
Maurizio M Munafo400.34