基于日志的DNS隧道检测系统的设计与实现
esign and Implementation of DNS Tunnel Detection System Based on Log
NS隧道是当前黑客进行网络攻击,窃取数据信息的主流方式之一,为了防范DNS隧道攻击,本文设计并实现了一套基于日志的DNS隧道检测系统。首先本文进行了DNS隧道检测的需求分析,设计出基于日志的DNS隧道检测方案;其次,根据需求分析给出了系统的总体架构,并分模块对DNS隧道检测系统进行了详细的设计与实现;最后,在实际网络环境中,对系统的各模块进行了功能测试。结果表明,该系统能有效检测出网络环境中的DNS隧道流量,降低运维成本。
NS tunnel is one of the main ways for hackers to attack network and steal data. In order to prevent DNS tunnel attack, this paper designs and implements a set of DNS tunnel detection system based on log. First of all, this paper analyzes the demand of DNS tunnel detection, and designs a log based DNS tunnel detection scheme; secondly, according to the demand analysis, the overall architecture of the system is given, and the detailed design and implementation of the DNS tunnel detection system is divided into modules; finally, in the actual network environment, the feature of each module of the system is tested. The results show that the system can effectively detect the DNS tunnel traffic in the network environment and reduce the operation and maintenance costs.
王琪、马严
通信
计算机技术网络安全NS隧道
omputer technologyNetwork securityDNS tunnel
王琪,马严.基于日志的DNS隧道检测系统的设计与实现[EB/OL].(2020-03-31)[2025-08-02].http://www.paper.edu.cn/releasepaper/content/202003-338.点此复制
评论