The domain name system (DNS) offers an ideal distributed database for big data mining related to different cyber security questions. Besides infrastructural problems, scalability issues, and security challenges related to the protocol itself, information from DNS is often required also for more nuanced cyber security questions. Against this backdrop, this paper discusses the fundamental characteristics of DNS in relation to cyber security and different research prototypes designed for passive but continuous DNS-based monitoring of domains and addresses. With this discussion, the paper also illustrates a few general software design aspects.
Jukka Ruohonen (Aalto University), Ville Leppänen (University of Turku): On the Design of a Simple Network Resolver for DNS Mining
Presented at the CompSysTech ’16, Proceedings of the 17th International Conference on Computer Systems and Technologies 2016, Palermo.