Mining IP to Domain Name Interactions to Detect DNS Flood Attacks on Recursive DNS Servers

Roberto Alonso1,2, Raúl Monroy3, Luis A Trejo4

  • 1Escuela de Ingeniería y Ciencias, Tecnologico de Monterrey, Carretera al Lago de Guadalupe Km. 3.5, Atizapán, Estado de México 52926, Mexico. roberto.alonso@itesm.mx.

Summary

This study introduces a new method to detect Distributed Denial of Service (DDoS) attacks on recursive Domain Name System (DNS) servers by analyzing query patterns. The approach leverages the social structure of DNS queries to identify malicious activity.