Large Scale DNS Analysis [chapter]

Samuel Marchal, Thomas Engel
2012 Lecture Notes in Computer Science  
In this paper we present an architecture for large scale DNS monitoring. The analysis of DNS traffic is becoming of first importance currently, as it allows to monitor the main part of the interactions on the Internet. DNS traffic can reveal anomalies such as worm infected hosts, botnets or spam participating hosts. The efficiency and the speed of detection of such anomalies rely on the capacity of DNS monitoring system to treat quickly huge quantity of data. We propose a system that leverages distributed processing and storage facilities.
doi:10.1007/978-3-642-30633-4_20 fatcat:yhc73tinxng47bvxsphfipxahe