Related Experiment Video
Updated: Mar 16, 2026

Automated Deployment of an Internet Protocol Telephony Service on Unmanned Aerial Vehicles Using Network Functions Virtualization
Published on: November 26, 2019
Mining IP to Domain Name Interactions to Detect DNS Flood Attacks on Recursive DNS Servers
Roberto Alonso1,2, Raúl Monroy3, Luis A Trejo4
1Escuela de Ingeniería y Ciencias, Tecnologico de Monterrey, Carretera al Lago de Guadalupe Km. 3.5, Atizapán, Estado de México 52926, Mexico. roberto.alonso@itesm.mx.
This study introduces a new method to detect Distributed Denial of Service (DDoS) attacks on recursive Domain Name System (DNS) servers by analyzing query patterns. The approach leverages the social structure of DNS queries to identify malicious activity.
Area of Science:
- Cybersecurity
- Network Security
- Computer Science
Background:
- The Domain Name System (DNS) is vital network infrastructure and a frequent target for cyberattacks.
- Existing research primarily focuses on higher-level DNS traffic analysis, neglecting the recursive DNS level.
- The recursive DNS level is understudied yet crucial for network integrity and security.
Purpose of the Study:
- To introduce a novel abstraction for recursive DNS traffic to detect flooding attacks, a type of Distributed Denial of Service (DDoS).
- To develop and validate an anomaly-based detection mechanism for identifying DDoS attacks at the recursive DNS level.
- To explore the potential of DNS traffic abstraction for detecting other network anomalies.
Main Methods:
- Developed a novel abstraction of recursive DNS traffic based on the observation that queries form social groups.
- Implemented an anomaly-based detection mechanism using features that capture the DNS social structure.
- Utilized a heuristic to estimate group composition within DNS query patterns.
Main Results:
- Successfully validated the detection mechanism in a simulated and controlled environment.
- Demonstrated the suitability of the proposed abstraction for detecting flooding attacks at the recursive DNS level.
- Achieved promising results in detecting other types of anomalies in recursive DNS servers through additional experiments.
Conclusions:
- This work is the first to successfully use a DNS traffic abstraction to detect flooding attacks at the recursive level.
- The proposed abstraction offers a promising new direction for securing recursive DNS servers against various threats.
- Further research into this abstraction can lead to enhanced detection of diverse network anomalies.
More Related Videos
11:19Label-Free Immunoprecipitation Mass Spectrometry Workflow for Large-scale Nuclear Interactome Profiling
Published on: November 17, 2019
07:14Tracking Infiltration Front Depth Using Time-lapse Multi-offset Gathers Collected with Array Antenna Ground Penetrating Radar
Published on: May 1, 2018
Related Concept Videos
Applications of GIS: Disaster Management and Emergency Response
Responses to Drought and Flooding
Immunoprecipitation
Chromatin Immunoprecipitation
Chromatin immunoprecipitation, also known as ChIP, is used to study protein-DNA or...