Research on DNS Anomaly Detection Technology Based on Multiple Features

QIN Huidong,YANG Jia,LI Xiaonan,MA Hao,LUO Ziyuan,GUO Qiang
DOI: https://doi.org/10.3724/sp.j.1249.2020.99036
2020-01-01
JOURNAL OF SHENZHEN UNIVERSITY SCIENCE AND ENGINEERING
Abstract:In this paper, we propose a local outlier factor (LOF) algorithm based on multi-dimensional timing characteristics for detecting abnormal source IPs of DNS. The algorithm is used to identify abnormal source IPs of the DNS traffic of a campus network. Based on the algorithm, we further introduce a multi-feature-based abnormal domain name detection method and efficiently improve the detection of DNS anomalies of the campus network.
What problem does this paper attempt to address?