A Detection and blocking system for suspicious DNS outbound query using RPZ

IR (HANDLE) Open Access

Bibliographic Information

Other Title
  • RPZを用いた不審なDNS外部クエリーの検知・遮断システムの一検討

Search this article

Description

Bot programs that send DNS query without using the DNS full resolvers in an organization network (direct outbound DNS query) have become a critical problem. In this paper, we purpose to detect and block such malicious direct outbound DNS queries. In order to solve the problem, we proposed a detection and blocking system using DNS RPZ (Response Policy Zone) and implemented a prototype system. Based on the evaluation results we confirmed the features

Journal

Details 詳細情報について

  • CRID
    1050856738261920512
  • ISSN
    24326380
    09135685
  • HANDLE
    2115/86957
  • Text Lang
    ja
  • Article Type
    journal article
  • Data Source
    • IRDB

Report a problem

Back to top