Back to Search Start Over

Proposal of Anomaly Detection for DNS Attacks Based on Packets Prediction Using LSTM

Authors :
Inaba Hiroyuki
Kimura Satoshi
Source :
IIAI-AAI
Publication Year :
2020
Publisher :
IEEE, 2020.

Abstract

DNS is an essential protocol of the Internet. However, DNS also tends to be used as the target of attacks, such as DNS Amplification Attack and Open Resolver Scanning due to its protocol. To detect these attacks, we present a novel anomaly detection method for DNS attacks based on the prediction values of DNS using LSTM(Long Short-Term Memory). Through the experiment, we compared the prediction accuracy of the sequential prediction method for short-term prediction and the batch prediction method for long-term prediction. Furthermore, we propose a dynamic threshold method that can be set automatically by using the error derived from training process. As a result, the sequential prediction method can predict with higher accuracy than the batch prediction method. We also show that the attacks can be detected by using the dynamic threshold method with the sequential prediction method.

Details

Database :
OpenAIRE
Journal :
2020 9th International Congress on Advanced Applied Informatics (IIAI-AAI)
Accession number :
edsair.doi...........3970af2de29d8a71fb02417d6cc148c5
Full Text :
https://doi.org/10.1109/iiai-aai50415.2020.00028