DNSAnomDet
Authors | |
---|---|
Year of publication | 2014 |
MU Faculty or unit | |
Attached files | |
Description | DNSAnomDet is a suite of scripts that automate detection of DNS traffic anomalies, using IP flows in the IPFIX format extended by information from DNS packets. Scripts focus on detection of cybersquatting, DNS amplification attacks, open DNS resolvers, malware domain queries, and DNS tunneling detection. |