Detecting anomalies in DNS protocol traces via Passive Testing and Process Mining

dc.contributor.authorSaint-Pierre Cortés, Cecilia
dc.contributor.authorCifuentes, F
dc.contributor.authorBustos-Jiménez, J.
dc.date.accessioned2022-05-13T19:15:18Z
dc.date.available2022-05-13T19:15:18Z
dc.date.issued2014
dc.description.abstractIn this article we present our first approach in using Passive Testing (used in protocol and software conformance checking) and Process Mining (used in enterprise workflow analysis) techniques for analyzing DNS operation traces. We propose a process approach for DNS protocol, modeling it as a sequence of structured activities, queries and responses that are executed by actors, in this case clients and servers, with the objective of exchange some valuable information. As an example, we applied our techniques over A Day in Internet Life DNS traces for showing how easily a mail bonnet attack can be discovered. We conclude that with our first approach this techniques have promising future in order to analyze DNS traces, and plan to extend the testing for conformance against the formal definition of DNS presented in the RFC 1035.
dc.fuente.origenIEEE
dc.identifier.doi10.1109/CNS.2014.6997534
dc.identifier.isbn978-1479958900
dc.identifier.urihttps://doi.org/10.1109/CNS.2014.6997534
dc.identifier.urihttps://ieeexplore.ieee.org/stamp/stamp.jsp?arnumber=6997534
dc.identifier.urihttps://repositorio.uc.cl/handle/11534/63882
dc.information.autorucEscuela de ingeniería ; Saint-Pierre Cortes, Cecilia Cristina ; S/I ; 224680
dc.language.isoen
dc.nota.accesoContenido parcial
dc.publisherIEEE
dc.relation.ispartofIEEE Conference on Communications and Network Security (2014 : San Francisco, CA, Estados Unidos)
dc.rightsacceso restringido
dc.subjectProtocols
dc.subjectTesting
dc.subjectServers
dc.subjectInternet
dc.subjectBusiness
dc.subjectElectronic mail
dc.subjectData mining
dc.titleDetecting anomalies in DNS protocol traces via Passive Testing and Process Mininges_ES
dc.typecomunicación de congreso
sipa.codpersvinculados224680
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Detecting anomalies in DNS protocol traces via Passive Testing and Process Mining.pdf
Size:
2.66 KB
Format:
Adobe Portable Document Format
Description: