Detecting network scanning through monitoring and manipulation of dns traffic

JH Jafarian, M Abolfathi, M Rahimian - IEEE Access, 2023 - ieeexplore.ieee.org
In this paper, we propose an approach for detecting internal and external network scanning
attacks on enterprise networks. In our approach, an inline scan detection system (SDS) …

Beyond The Gates: An Empirical Analysis of {HTTP-Managed} Password Stealers and Operators

A Avgetidis, O Alrawi, K Valakuzhy, C Lever… - 32nd USENIX security …, 2023 - usenix.org
Password Stealers (Stealers) are commodity malware that specialize in credential theft. This
work presents a large-scale longitudinal study of Stealers and their operators. Using a …

View from above: exploring the malware ecosystem from the upper DNS hierarchy

A Faulkenberry, A Avgetidis, Z Ma, O Alrawi… - Proceedings of the 38th …, 2022 - dl.acm.org
This work explores authoritative DNS (AuthDNS) as a new measurement perspective for
studying the large-scale epidemiology of the malware ecosystem—when and where …

Wolf in Sheep's Clothing: Evaluating Security Risks of the Undelegated Record on DNS Hosting Services

F Zhang, Y Zhang, B Liu, E Alowaisheq, L Ying… - Proceedings of the …, 2023 - dl.acm.org
Leveraging DNS for covert communications is appealing since most networks allow DNS
traffic, especially the ones directed toward renowned DNS hosting services. Unfortunately …

Enabling multi-hop ISP-hypergiant collaboration

C Munteanu, O Gasser, I Poese… - Proceedings of the …, 2023 - dl.acm.org
Today, there is an increasing number of peering agreements between Hypergiants and
networks that benefit millions of end-user. However, the majority of Autonomous Systems do …

Towards a Behavioral and Privacy Analysis of ECS for IPv6 DNS Resolvers

L Nie, L He, G Song, H Gao, C Li… - … on Network and …, 2022 - ieeexplore.ieee.org
The Domain Name System (DNS) is critical to Internet communications. EDNS Client Subnet
(ECS), a DNS extension, allows recursive resolvers to include client subnet information in …

[PDF][PDF] Detecting Network Scanning Through Monitoring and Manipulation of DNS Traffic

M RAHIMIAN - academia.edu
In this paper, we propose an approach for detecting internal and external network scanning
attacks on enterprise networks. In our approach, an inline scan detection system (SDS) …