Conference paper

KOVÁČIK Michal. Detekcia sieťových anomálií s využitím DNS dát. In: Počítačové architektury a diagnostika. Teplá: University of West Bohemia in Pilsen, 2013, pp. 33-38. ISBN 978-80-01-05106-1.
Publication language:sk
Original title:Detekcia sieťových anomálií s využitím DNS dát
Title (cs):Detekce síťových anomálií s využitím DNS dat
Title (en):Network anomaly detection with use of DNS data
Proceedings:Počítačové architektury a diagnostika
Conference:Počítačové architektury a diagnostika 2013
Place:Teplá, CZ
Publisher:University of West Bohemia in Pilsen
anomaly detection, security incident, DNS service, network attack
DNS service is base structural block of Internet, because it is critical for correct functionality of many existing services,
Most of the communication on Internet starts with several DNS queries. Considering it's basic task, which is translation of domain names to IP addresses, is this service target of high amount of malicious activities. This article deals with actually present anomalous behaviour, which directly uses or abuses DNS service. Importance of DNS service is discussed, it's vulnerabilities and recent internet attacks. Main part of the article is analyse of possible attacks on DNS and examples of it's abuse. Along, some existing anomaly detection and attack detection methods are introduced. Article also includes chapter about heading of my dissertation thesis.

