DNS: A Statistical Analysis of Name Server Traffic at Local Network-to-Internet Connections
نویسندگان
چکیده
This paper puts forward a purely statistical analysis of name server traffic captured at four different locations: two links to residential networks, and two to the Dutch academic and research institute. Analysis of the system can give insight in the use and performance of the protocol, which is helpful for future improvement. Multiple analyses can show the development of the performance over time and help create quality models. The analysis shows that a little more than 12% of all queries are not answered upon. Three quarters of the lookups are successful: they give the client the correct IP address mapping for the requested hostname. 90% is answered within 275 ms, with an average of 152 ms. In 9% of all cases, clients ask for a hostname which does not exist. At one of the locations, a client is discovered which sends queries to two DNS servers at a remarkable rate: one each 11 to 22 ms.
منابع مشابه
An End-Host View on Local Traffic at Home and Work
This paper compares local and wide-area traffic from end-hosts connected to different home and work networks. We base our analysis on network and application traces collected from 47 end-hosts for at least one week. We compare traffic patterns in terms of number of connections, bytes, duration, and applications. Not surprisingly, wide-area traffic dominates local traffic for most users. Local c...
متن کاملSCALABLE TECHNIQUES FOR ANOMALY DETECTION A Dissertation by SANDEEP YADAV
Computer networks are constantly being attacked by malicious entities for various reasons. Network based attacks include but are not limited to, Distributed Denial of Service (DDoS), DNS based attacks, Cross-site Scripting (XSS) etc. Such attacks have exploited either the network protocol or the end-host software vulnerabilities for perpetration. Current network traffic analysis techniques empl...
متن کاملDNS-based Internet Client Clustering and Characterization
This paper proposes a novel protocol which uses the Internet Domain Name System (DNS) to partition Web clients into disjoint sets, each of which is associated with a single DNS server. We de ne an L-DNS cluster to be a grouping of Web Clients that use the same Local DNS server to resolve Internet host names. We identify such clusters in real-time using data obtained from a Web Server in conjunc...
متن کاملDetecting Bot Networks Based On HTTP And TLS Traffic Analysis
Abstract— Bot networks are a serious threat to cyber security, whose destructive behavior affects network performance directly. Detecting of infected HTTP communications is a big challenge because infected HTTP connections are clearly merged with other types of HTTP traffic. Cybercriminals prefer to use the web as a communication environment to launch application layer attacks and secretly enga...
متن کاملSigcomm: G: Behind the Curtain – The importance of replica selection in next generation networks
1. PROBLEM & MOTIVATION Smartdevices are becoming the primary or only Internet point of access for an ever larger fraction of users. Nearly a quarter of current web traffic is mobile, and recent industry studies have estimated a fourfold increase in global mobile data traffic by 2018, mainly driven by data demands and the growing number of smart phones and tablets [7]. Content delivery networks...
متن کامل