Further Aspects of Passive DNS
Datamining, visualization and alternative implementations Sebastien Tricaud (PicViz), Alexandre Dulaunoy (CIRCL.lu),
- L. Aaron Kaplan (CERT.at),
Further Aspects of Passive DNS Datamining, visualization and - - PowerPoint PPT Presentation
Further Aspects of Passive DNS Datamining, visualization and alternative implementations Sebastien Tricaud (PicViz), Alexandre Dulaunoy (CIRCL.lu), L. Aaron Kaplan (CERT.at), David Durvaux (CERT.be), John Kristoff (Team Cymru) June 19, 2012
1Except if an application abuses DNS answers to track back their users. 2 of 26
3 of 26
4 of 26
5 of 26
6 of 26
7 of 26
8 of 26
aPresented at FIRST 2005 bgithub.com/adulau/pdns-toolkit/ caccess upon request
ahttps://dnsdb.isc.org/ 9 of 26
10 of 26
11 of 26
2exception → only used for data store snapshot 12 of 26
13 of 26
14 of 26
15 of 26
16 of 26
17 of 26
18 of 26
19 of 26
3Shannon entropy 20 of 26
4Shannon entropy 21 of 26
22 of 26
23 of 26
24 of 26
25 of 26
26 of 26