期刊文献+

基于开源软件的DNS查询日志分析系统 被引量:1

DNS Query Log Analysis System Based on Open Source Software
下载PDF
导出
摘要 域名系统(domain name system,DNS)是互联网的核心基础服务,服务的健壮性和安全性非常重要.针对高等学校的DNS配置中存在的问题,提出了一个基于开源软件的DNS查询日志分析系统,给出构建DNS集群自动化部署的方案,利用开源工具监控DNS的配置信息和运行状态,并利用大数据分析工具结合少量的编程生成查询日志的可视化图表.实际运用后表明,该系统通过横向扩展可应对每日上亿条数据的实时分析要求.DNS服务整体架构清晰,安全性提高,用户的上网日志可实时统计展示,为分析DNS服务的运行状态、攻击预警、网络性能调优等方面提供了帮助. Domain name system is one of the most important parts of the Internet.Robustness and security of the service are extremely important. However, numerous problems exist in the University's DNS configuration. This paper, through the setup experience of Xiamen University,proposes a DNS query log analysis system based on open source software.This system gives the best practice of how to automatically build DNS cluster, the method of monitoring and examining the DNS configuration and running status by using open source tools.Additionally, the system offers the query log visualizations generated by using big data analysis tools combined with a small amount of programming.Furthermore, the system can deal with real-time analysis of more than one hundred million bits of data daily through horizontal expansion.After using the system,DNS service exhibits a clear structure and security.The query log statistics shows in real time.All these features offer great help for analyzing the running status of the DNS server, showing attack warning, and optimizing network performance.
作者 郑海山 ZHENG Haishan(Information & Network Center,Xiamen University,Xiamen 361005,China)
出处 《厦门大学学报(自然科学版)》 CAS CSCD 北大核心 2017年第2期252-258,共7页 Journal of Xiamen University:Natural Science
基金 福建省中青年教师教育科研项目(JAT160019)
关键词 域名系统 BIND 大数据 日志分析 可视化 部署自动化 domain name system bind big data log analysis visualization automation deployment
  • 相关文献

参考文献3

二级参考文献15

  • 1Danzig P B, Obraezka K, Kumar A. An analysis of wide-area name server traffic: A study of the internet domain name system [C]//ACM SIGCOMM Computer Communication Review. New York, 1992, 22(4): 281-292.
  • 2Wessels D, Fomenkov M. Wow, that's a lot of packets [C]//Proc Passive and Active Network Measurement Workshop (PAM). San Diego, 2003.
  • 3Brownlee N, Claffy K, Nemeth E. DNS measurements at a root server [C]//6th Global Internet Symposium. San Antonio, TX, 2001.
  • 4Xu W, Kirkpatrick B, Lacoste-Julien S. Analyzing root DNS traffie [EB/OL] (2004). http://www. eecs. berkeley. edu/ bbkirk/papers/es262a- 2004. pdf.
  • 5Jung J, Sit E, Balakrishnan H, et al. DNS performance and the effectiveness of caching [J]. IEEE/ACM Trans on Networking, 2002, 10(5): 589-603.
  • 6Ishibashi K, Toyono T, Matsuoka H, et al. Measurement of DNS traffic caused by DDoS attack [C]// Proc the Symposium on Applications and the Internet Workshops. Washington, 2005 : 118 - 121.
  • 7Ishibashi K, Toyono T, Toyama K, et al. Detecting mass-mailing worm infected hosts by mining DNS traffic data [C]//Proc the 2005 ACM SIGCOMM Workshop on Mining Network Data. Philadelphia, 2005: 159 - 164.
  • 8WhiteT.Hadoop权威指南.周敏奇,王晓玲,金澈清等译.北京:清华大学出版社,2011.
  • 9Agrawal D, Bernstein P, Bertino E, et al. Challenges and opportunities with big data. http://cra.org/ccc/docs/init/ bigdatawhitepaper.pdf, 2015.
  • 10诸葛建伟,韩心慧,周勇林,叶志远,邹维.僵尸网络研究[J].软件学报,2008,19(3):702-715. 被引量:157

共引文献70

同被引文献10

引证文献1

二级引证文献3

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部