Understanding the Challenges of Blocking Unnamed Network Traffic.

Kaspar Hageman, Egon Kidmose, René Rydhof Hansen, Jens Myrup Pedersen

Publikation: Bidrag til bog/antologi/rapport/konference proceedingKonferenceartikel i proceedingForskningpeer review

Network traffic that is not preceded by any Domain Name System (DNS) resolutions is referred to as unnamed traffic. Any DNS-based security system is ineffective against malicious content distributed through this traffic. In this paper, we introduce a novel method for identifying unnamed traffic based on the correlation of flows and DNS responses extracted from raw network traces. We describe two challenges that affect the validity of our method, and how to handle them. By applying our method to a one-week trace of network traffic, we illustrate that unnamed traffic is ubiquitous in a university network across nearly all client systems, destination IP addresses, and destination services. We conclude by presenting several open problems that prevent us from blocking unnamed traffic for security reasons.
TitelNOMS 2022-2022 IEEE/IFIP Network Operations and Management Symposium : Network and Service Management in the Era of Cloudification, Softwarization and Artificial Intelligence, NOMS 2022
RedaktørerPal Varga, Lisandro Zambenedetti Granville, Alex Galis, Istvan Godor, Noura Limam, Prosper Chemouil, Jerome Francois, Marc-Oliver Pahl
ForlagIEEE (Institute of Electrical and Electronics Engineers)
ISBN (Trykt)978-1-6654-0602-4
ISBN (Elektronisk)9781665406017
StatusUdgivet - 2022
BegivenhedIEEE Symposium on Network Operations and Management - Budapest, Ungarn
Varighed: 25 apr. 202329 apr. 2023


KonferenceIEEE Symposium on Network Operations and Management
NavnIEEE/IFIP Network Operations and Management Symposium

