FlowDNS: Correlating Netflow and DNS Streams at Scale

11/10/2022
by   Aniss Maghsoudlou, et al.
0

Knowing customer's interests, e.g. which Video-On-Demand (VoD) or Social Network services they are using, helps telecommunication companies with better network planning to enhance the performance exactly where the customer's interests lie, and also offer the customers relevant commercial packages. However, with the increasing deployment of CDNs by different services, identification, and attribution of the traffic on network-layer information alone becomes a challenge: If multiple services are using the same CDN provider, they cannot be easily distinguished based on IP prefixes alone. Therefore, it is crucial to go beyond pure network-layer information for traffic attribution. In this work, we leverage real-time DNS responses gathered by the clients' default DNS resolvers. Having these DNS responses and correlating them with network-layer headers, we are able to translate CDN-hosted domains to the actual services they belong to. We design a correlation system for this purpose and deploy it at a large European ISP. With our system, we can correlate an average of 81.7 corresponding services, without any loss on our live data streams. Our correlation results also show that 0.5 malformatted, spamming, or phishing domain names. Moreover, ISPs can correlate the results with their BGP information to find more details about the origin and destination of the traffic. We plan to publish our correlation software for other researchers or network operators to use.

READ FULL TEXT
research
09/16/2013

A Neural Network based Approach for Predicting Customer Churn in Cellular Network Services

Marketing literature states that it is more costly to engage a new custo...
research
11/12/2022

We have to go back: A Historic IP Attribution Service for Network Measurement

Researchers and practitioners often face the issue of having to attribut...
research
05/02/2023

Network Error Logging: HTTP Archive Analysis

Network Error Logging helps web server operators detect operational prob...
research
12/11/2022

Bypassing Content-based internet packages with an SSL/TLS Tunnel, SNI Spoofing, and DNS spoofing

Internet Service Providers (ISPs) are increasingly offering content-base...
research
04/26/2018

iTeleScope: Intelligent Video Telemetry and Classification in Real-Time using Software Defined Networking

Video continues to dominate network traffic, yet operators today have po...
research
07/17/2023

Live Long and Prosper:Analyzing Long-Lived MOAS Prefixes in BGP

BGP exchanges reachability information in the form of prefixes, which ar...
research
11/02/2019

FCEM: A Novel Fast Correlation Extract Model For Real Time Steganalysis of VoIP Stream via Multi-head Attention

Extracting correlation features between codes-words with high computatio...

Please sign up or login with your details

Forgot password? Click here to reset