Back to Search
Start Over
Proposal of Anomaly Detection for DNS Attacks Based on Packets Prediction Using LSTM
- Source :
- IIAI-AAI
- Publication Year :
- 2020
- Publisher :
- IEEE, 2020.
-
Abstract
- DNS is an essential protocol of the Internet. However, DNS also tends to be used as the target of attacks, such as DNS Amplification Attack and Open Resolver Scanning due to its protocol. To detect these attacks, we present a novel anomaly detection method for DNS attacks based on the prediction values of DNS using LSTM(Long Short-Term Memory). Through the experiment, we compared the prediction accuracy of the sequential prediction method for short-term prediction and the batch prediction method for long-term prediction. Furthermore, we propose a dynamic threshold method that can be set automatically by using the error derived from training process. As a result, the sequential prediction method can predict with higher accuracy than the batch prediction method. We also show that the attacks can be detected by using the dynamic threshold method with the sequential prediction method.
- Subjects :
- business.industry
Computer science
Network packet
ComputerSystemsOrganization_COMPUTER-COMMUNICATIONNETWORKS
Process (computing)
020206 networking & telecommunications
02 engineering and technology
Set (abstract data type)
Resolver
0202 electrical engineering, electronic engineering, information engineering
020201 artificial intelligence & image processing
The Internet
Anomaly detection
DNS spoofing
business
Protocol (object-oriented programming)
Algorithm
Subjects
Details
- Database :
- OpenAIRE
- Journal :
- 2020 9th International Congress on Advanced Applied Informatics (IIAI-AAI)
- Accession number :
- edsair.doi...........3970af2de29d8a71fb02417d6cc148c5
- Full Text :
- https://doi.org/10.1109/iiai-aai50415.2020.00028