Scrutinizing a Country using Passive DNS and Picviz
- r how to analyze big dataset without loosing your mind
Scrutinizing a Country using Passive DNS and Picviz or how to - - PowerPoint PPT Presentation
Scrutinizing a Country using Passive DNS and Picviz or how to analyze big dataset without loosing your mind Sebastien Tricaud, Alexandre Dulaunoy March 10, 2012 Disclaimer Passive DNS is a technique to collect only valid answers from
1Except if the web application abused DNS answers to track back their users. 2 of 38
an IP address
has the DNS properties MX A CNAME NS announced by an ASN peering with stability has been tracked by Zeus Tracker AMaDa Blocklist dshield.org has been reported to Abuse Helper CSIRT RTIR
3 of 38
4 of 38
an IP address
has the DNS properties MX A CNAME NS announced by an ASN peering with stability has been tracked by Zeus Tracker AMaDa Blocklist dshield.org has been reported to Abuse Helper CSIRT RTIR
5 of 38
2exception → only used for data store snapshot 6 of 38
7 of 38
8 of 38
9 of 38
an IP address
has the DNS properties MX A CNAME NS announced by an ASN peering with stability has been tracked by Zeus Tracker AMaDa Blocklist dshield.org has been reported to Abuse Helper CSIRT RTIR
10 of 38
11 of 38
12 of 38
13 of 38
14 of 38
15 of 38
16 of 38
17 of 38
18 of 38
19 of 38
20 of 38
21 of 38
22 of 38
23 of 38
24 of 38
25 of 38
26 of 38
27 of 38
3Shannon entropy 28 of 38
4Shannon entropy 29 of 38
30 of 38
31 of 38
32 of 38
33 of 38
34 of 38
35 of 38
36 of 38
37 of 38
38 of 38