z-logo
open-access-imgOpen Access
Entropy-Based Evaluation of DNS Activity for Threat Hunting
Author(s) -
Argyrios Alexopoulos
Publication year - 2021
Language(s) - English
DOI - 10.47260/jamb/1112
Subject(s) - domain name system , cyberspace , computer science , computer security , domain name , anomaly detection , entropy (arrow of time) , data mining , the internet , world wide web , physics , quantum mechanics
The paper documents, based mainly on published papers where a consistent mathematical description of cyberspace and various types of Cyber-Attacks and protection measures are presented, a mathematical approach for Cyber Threat Hunting using Domain Name System (DNS) observations. After referring to the various Advanced Persistent Threat (APT) hunting techniques we propose a high level, mainly, entropy-based technique for detecting the existence of various threat vectors in our networks, demystifying DNS Anomalies.Keywords: Domain Name System (DNS), Advanced Persistent Threat (APT) actors, Entropy, Anomaly Detection.

The content you want is available to Zendy users.

Already have an account? Click here to sign in.
Having issues? You can contact us here