{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,25]],"date-time":"2026-01-25T13:21:05Z","timestamp":1769347265210,"version":"3.49.0"},"reference-count":45,"publisher":"MDPI AG","issue":"8","license":[{"start":{"date-parts":[[2016,8,17]],"date-time":"2016-08-17T00:00:00Z","timestamp":1471392000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>The Domain Name System (DNS) is a critical infrastructure of any network, and, not surprisingly a common target of cybercrime. There are numerous works that analyse higher level DNS traffic to detect anomalies in the DNS or any other network service. By contrast, few efforts have been made to study and protect the recursive DNS level. In this paper, we introduce a novel abstraction of the recursive DNS traffic to detect a flooding attack, a kind of Distributed Denial of Service (DDoS). The crux of our abstraction lies on a simple observation: Recursive DNS queries, from IP addresses to domain names, form social groups; hence, a DDoS attack should result in drastic changes on DNS social structure. We have built an anomaly-based detection mechanism, which, given a time window of DNS usage, makes use of features that attempt to capture the DNS social structure, including a heuristic that estimates group composition. Our detection mechanism has been successfully validated (in a simulated and controlled setting) and with it the suitability of our abstraction to detect flooding attacks. To the best of our knowledge, this is the first time that work is successful in using this abstraction to detect these kinds of attacks at the recursive level. Before concluding the paper, we motivate further research directions considering this new abstraction, so we have designed and tested two additional experiments which exhibit promising results to detect other types of anomalies in recursive DNS servers.<\/jats:p>","DOI":"10.3390\/s16081311","type":"journal-article","created":{"date-parts":[[2016,8,17]],"date-time":"2016-08-17T10:23:21Z","timestamp":1471429401000},"page":"1311","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":14,"title":["Mining IP to Domain Name Interactions to Detect DNS Flood Attacks on Recursive DNS Servers"],"prefix":"10.3390","volume":"16","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5481-1760","authenticated-orcid":false,"given":"Roberto","family":"Alonso","sequence":"first","affiliation":[{"name":"Escuela de Ingenier\u00eda y Ciencias, Tecnologico de Monterrey, Carretera al Lago de Guadalupe Km. 3.5, Atizap\u00e1n, Estado de M\u00e9xico 52926, Mexico"},{"name":"Department of Informatics, Technical University of Munich, Boltzmannstr. 3, 85748 Garching, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3465-995X","authenticated-orcid":false,"given":"Ra\u00fal","family":"Monroy","sequence":"additional","affiliation":[{"name":"Escuela de Ingenier\u00eda y Ciencias, Tecnologico de Monterrey, Carretera al Lago de Guadalupe Km. 3.5, Atizap\u00e1n, Estado de M\u00e9xico 52926, Mexico"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9741-4581","authenticated-orcid":false,"given":"Luis","family":"Trejo","sequence":"additional","affiliation":[{"name":"Escuela de Ingenier\u00eda y Ciencias, Tecnologico de Monterrey, Carretera al Lago de Guadalupe Km. 3.5, Atizap\u00e1n, Estado de M\u00e9xico 52926, Mexico"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2016,8,17]]},"reference":[{"key":"ref_1","unstructured":"Antonakakis, M., Perdisci, R., Nadji, Y., Vasiloglou, N., Abu-Nimeh, S., Lee, W., and Dagon, D. (2012, January 8\u201310). From Throw-Away Traffic to Bots: Detecting the Rise of DGA-Based Malware. Proceedings of the 21st USENIX Security Symposium (USENIX Security 12), Bellevue, WA, USA."},{"key":"ref_2","first-page":"714","article-title":"Early Detection of Malicious Flux Networks via Large-Scale Passive DNS Traffic Analysis","volume":"9","author":"Perdisci","year":"2012","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Kr\u00e4mer, L., Krupp, J., Makita, D., Nishizoe, T., Koide, T., Yoshioka, K., and Rossow, C. (2015, January 2\u20134). AmpPot: Monitoring and Defending Against Amplification DDoS Attacks. Research in Attacks, Intrusions, and Defenses, Proceedings of the 18th International Symposium, RAID 2015, Kyoto, Japan.","DOI":"10.1007\/978-3-319-26362-5_28"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"41","DOI":"10.1145\/1452335.1452341","article-title":"A day at the root of the internet","volume":"38","author":"Castro","year":"2008","journal-title":"ACM SIGCOMM Comput. Commun. Rev."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"43","DOI":"10.1109\/TNET.2014.2358637","article-title":"Reexamining DNS from a Global Recursive Resolver Perspective","volume":"24","author":"Gao","year":"2014","journal-title":"IEEE\/ACM Trans. Netw."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Herzberg, A., and Shulman, H. (2014, January 8\u201312). DNS Authentication as a Service: Preventing Amplification Attacks. Proceedings of the 30th Annual Computer Security Applications Conference, New York, NY, USA.","DOI":"10.1145\/2664243.2664281"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Schomp, K., Callahan, T., Rabinovich, M., and Allman, M. (2013, January 23\u201325). On Measuring the Client-side DNS Infrastructure. Proceedings of the 2013 Conference on Internet Measurement Conference, New York, NY, USA.","DOI":"10.1145\/2504730.2504734"},{"key":"ref_8","unstructured":"Cheung, S. (2005). Denial of Service against the Domain Name System: Threats and Countermeasures, SRI International. Technical Report SRI-CSL-05-02."},{"key":"ref_9","unstructured":"Infoblox. Available online: https:\/\/www.infoblox.com\/sites\/infobloxcom\/files\/resources\/infoblox-ebook-top-ten-dns-attacks0.pdf."},{"key":"ref_10","unstructured":"Zeifman, I. Available online: https:\/\/www.incapsula.com\/blog\/massive-dns-ddos-flood.html."},{"key":"ref_11","unstructured":"Balakrichenan, S. (2014). Random Qnames\u2014Dafa888 DoS Attack, Association Fran\u00e7aise pour le Nommage Internet en Coop\u00e9ration (AFNIC). Technical Report."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"388","DOI":"10.1006\/jagm.2001.1199","article-title":"On Bipartite and Multipartite Clique Problems","volume":"41","author":"Dawande","year":"2001","journal-title":"J. Algorithms"},{"key":"ref_13","first-page":"489","article-title":"On the NP-Completeness of Computing the Commonality Amongst the Objects upon which a Collection of Agents has Performed an Action","volume":"17","author":"Alonso","year":"2013","journal-title":"Comput. Sist."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"651","DOI":"10.1016\/S0166-218X(03)00333-0","article-title":"The maximum edge biclique problem is NP-complete","volume":"131","author":"Peeters","year":"2003","journal-title":"Discret. Appl. Math."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Yannakakis, M. (1978, January 1\u20133). Node- and Edge-Deletion NP-Complete Problems. Proceedings of the 10th Annual ACM Symposium on Theory of Computing, San Diego, CA, USA.","DOI":"10.1145\/800133.804355"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"789","DOI":"10.1007\/11925231_75","article-title":"A Hybrid Segmentation Method Applied to Color Images and 3D Information","volume":"Volume 4293","author":"Gelbukh","year":"2006","journal-title":"Lecture Notes in Computer Science"},{"key":"ref_17","unstructured":"Alonso, R. (2015). A Social Network Based Model to Detect Anomalies on DNS Servers. [Ph.D. Thesis, Tecnol\u00f3gico de Monterrey]."},{"key":"ref_18","unstructured":"K\u00fchrer, M., Hupperich, T., Rossow, C., and Holz, T. (2014, January 20\u201322). Exit from Hell? Reducing the Impact of Amplification DDoS Attacks. Proceedings of the 23rd USENIX Security Symposium (USENIX Security 14), San Diego, CA, USA."},{"key":"ref_19","unstructured":"Weber, R. (2014). Zeroing in on Zero Days, Nominium. Technical Report."},{"key":"ref_20","unstructured":"Rahbarinia, B., Perdisci, R., Antonakakis, M., and Dagon, D. (2013, January 12). SinkMiner: Mining Botnet Sinkholes for Fun and Profit. Presented at the 6th USENIX Workshop on Large-Scale Exploits and Emergent Threats, Washington, DC, USA."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Perdisci, R., Corona, I., Dagon, D., and Lee, W. (2009, January 7\u201311). Detecting Malicious Flux Service Networks through Passive Analysis of Recursive DNS Traces. Proceedings of the Twenty-Fifth Annual Computer Security Applications Conference (ACSAC 2009), Honolulu, HI, USA.","DOI":"10.1109\/ACSAC.2009.36"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Rossow, C. (2014, January 23\u201326). Amplification Hell: Revisiting Network Protocols for DDoS Abuse. Proceedings of the 2014 Network and Distributed System Security (NDSS) Symposium, San Diego, CA, USA.","DOI":"10.14722\/ndss.2014.23233"},{"key":"ref_23","first-page":"2825","article-title":"Scikit-learn: Machine Learning in Python","volume":"12","author":"Pedregosa","year":"2011","journal-title":"J. Mach. Learn. Res."},{"key":"ref_24","unstructured":"Weimer, F. (July, January 26). Passive DNS Replication. Proceedings of the 17th FIRST Conference on Computer Security Incident Handling, Singapore."},{"key":"ref_25","unstructured":"Antonakakis, M., Perdisci, R., Dagon, D., Lee, W., and Feamster, N. (2010, January 11\u201313). Building a Dynamic Reputation System for DNS. Proceedings of the 19th USENIX Conference on Security, Berkeley, CA, USA."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Bilge, L., Sen, S., Balzarotti, D., Kirda, E., and Kruegel, C. (2014). Exposure: A Passive DNS Analysis Service to Detect and Report Malicious Domains. ACM Trans. Inf. Syst. Secur., 16.","DOI":"10.1145\/2584679"},{"key":"ref_27","unstructured":"Antonakakis, M., Perdisci, R., Lee, W., Vasiloglou, N., and Dagon, D. (2011, January 8\u201312). Detecting Malware Domains at the Upper DNS Hierarchy. Proceedings of the 20th USENIX Conference on Security, Berkeley, CA, USA."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Chen, Y., Antonakakis, M., Perdisci, R., Nadji, Y., Dagon, D., and Lee, W. (2014, January 23\u201326). DNS Noise: Measuring the Pervasiveness of Disposable Domains in Modern DNS Traffic. Proceedings of the 2014 44th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks, Atlanta, GA, USA.","DOI":"10.1109\/DSN.2014.61"},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Kountouras, A., Kintis, P., Lever, C., Chen, Y., Nadji, Y., Dagon, D., and Antonakakis, M. (2016, January 19\u201321). Enabling Network Security Through Active DNS Datasets. Research in Attacks, Intrusions, and Defenses, Proceedings of the 19th International Symposium (RAID 2016), Evry, France.","DOI":"10.1007\/978-3-319-45719-2_9"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Rahman, M.R., Hu, Y., Wu, S.F., and Chuah, C.N. (2012, January 14\u201316). Social-Aware DNS: First Step towards Future Internet. Proceedings of the 2012 International Conference on Social Informatics (SocialInformatics), Washington, DC, USA.","DOI":"10.1109\/SocialInformatics.2012.61"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Sankararaman, S., Chen, J., Subramanian, L., and Ramasubramanian, V. (2012, January 3\u20137). TrickleDNS: Bootstrapping DNS security using social trust. Proceedings of the 2012 Fourth International Conference on Communication Systems and Networks (COMSNETS 2012), Bangalore, India.","DOI":"10.1109\/COMSNETS.2012.6151334"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Mitamura, T., and Yoshida, K. (2012, January 10). Viewers\u2019 Side Analysis of Social Interests. Proceedings of the 2012 IEEE 12th International Conference on Data Mining Workshops, Brussels, Belgium.","DOI":"10.1109\/ICDMW.2012.28"},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"2839","DOI":"10.1109\/TKDE.2015.2419653","article-title":"Spatio-Temporal Analysis of Passive Consumption in Internet Media","volume":"27","author":"Anand","year":"2015","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"ref_34","unstructured":"Vaughn, R., and Evron, G. DNS Amplification Attacks. Available online: http:\/\/crt.io\/DNS-Amplification-Attacks.pdf."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"475","DOI":"10.1016\/j.cose.2013.10.001","article-title":"DNS amplification attack revisited","volume":"39","author":"Anagnostopoulos","year":"2013","journal-title":"Comput. Secur."},{"key":"ref_36","unstructured":"Vixie, P., and Schryver, V. DNS Response Rate Limiting (DNS RRL). Available online: http:\/\/ss.vix.su\/~vixie\/isc-tn-2012-1.txt."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Kambourakis, G., Moschos, T., Geneiatakis, D., and Gritzalis, S. (2007, January 27\u201328). A Fair Solution to DNS Amplification Attacks. Proceedings of the IEEE Computer Society Second International Workshop on Digital Forensics and Incident Analysis, Samos, Greece.","DOI":"10.1109\/WDFIA.2007.4299371"},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Di Paola, S., and Lombardo, D. (2011, January 7\u20138). Protecting against DNS Reflection Attacks with Bloom Filters. Detection of Intrusions and Malware, and Vulnerability Assessment, Proceedings of the 8th International Conference (DIMVA 2011), Amsterdam, The Netherlands.","DOI":"10.1007\/978-3-642-22424-9_1"},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1016\/j.compbiolchem.2015.02.010","article-title":"Tumor stratification by a novel graph-regularized bi-clique finding algorithm","volume":"57","author":"Adl","year":"2015","journal-title":"Comput. Biol. Chem."},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1186\/1471-2105-15-110","article-title":"On finding bicliques in bipartite graphs: A novel algorithm and its application to the integration of diverse biological data types","volume":"15","author":"Zhang","year":"2014","journal-title":"BMC Bioinform."},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Sim, K., Li, J., Gopalkrishnan, V., and Liu, G. (2006, January 18\u201322). Mining Maximal Quasi-Bicliques to Co-Cluster Stocks and Financial Ratios for Value Investment. Proceedings of the Sixth International Conference on Data Mining (ICDM\u201906), Hong Kong, China.","DOI":"10.1109\/ICDM.2006.111"},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Beutel, A., Xu, W., Guruswami, V., Palow, C., and Faloutsos, C. (2013, January 13\u201317). CopyCatch: Stopping Group Attacks by Spotting Lockstep Behavior in Social Networks. Proceedings of the 22nd International Conference on World Wide Web, Rio de Janeiro, Brazil.","DOI":"10.1145\/2488388.2488400"},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Liu, H.F., Su, C.T., and Chu, A.C. Fast Quasi-biclique Mining with Giraph. Proceedings of the 2013 IEEE International Congress on Big Data, Santa Clara, CA, USA.","DOI":"10.1109\/BigData.Congress.2013.53"},{"key":"ref_44","unstructured":"Alonso, R., Monroy, R., Trejo, L., Sanchez, E., and Vazquez, J. (2009, January 9\u201313). How Social Networks can help to Detect DDoS attacks on DNS Servers. Proceedings of the 2009 Artificial Intelligence and Applications on 3rd Workshop in Computer Security (WSEC\u201909), Guanajuato, Mexico."},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Deri, L., Mainardi, S., Martinelli, M., and Gregori, E. (2013, January 1\u20135). Graph theoretical models of DNS traffic. Proceedings of the 2013 9th International Wireless Communications and Mobile Computing Conference (IWCMC), Sardinia, Italy.","DOI":"10.1109\/IWCMC.2013.6583721"}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/16\/8\/1311\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T19:28:37Z","timestamp":1760210917000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/16\/8\/1311"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,8,17]]},"references-count":45,"journal-issue":{"issue":"8","published-online":{"date-parts":[[2016,8]]}},"alternative-id":["s16081311"],"URL":"https:\/\/doi.org\/10.3390\/s16081311","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016,8,17]]}}}