2008Unpublished venueOpen access

Measuring and Detecting Fast-Flux Service Networks

Thorsten Holz, Christian Gorecki, Konrad Rieck, Felix Freiling

Open full text 314 citations

Abstract

We present the first empirical study of fast-flux service networks (FFSNs), a newly emerging and still not widely-known phenomenon in the Internet. FFSNs employ DNS to establish a proxy network on compromised machines through which illegal online services can be hosted with very high availability. Through our measurements we show that the threat which FFSNs pose is significant: FFSNs oc-cur on a worldwide scale and already host a substantial percentage of online scams. Based on analysis of the prin-ciples of FFSNs, we develop a metric with which FFSNs can be effectively detected. Considering our detection technique we also discuss possible mitigation strategies. 1

About this research paper

What this paper is about

We present the first empirical study of fast-flux service networks (FFSNs), a newly emerging and still not widely-known phenomenon in the Internet. FFSNs employ DNS to establish a proxy network on compromised machines through which illegal online services can be hosted with very high availability. Through our measurements we show that the threat which FFSNs pose is significant: FFSNs oc-cur on a worldwide scale and already host a substantial percentage of online scams. Based on analysis of the prin-ciples of FFSNs, we develop a metric with which FFSNs can be effectively detected. Considering our detection technique we also discuss possible mitigation strategies. 1

Why it matters

OpenAlex reports 314 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

We present the first empirical study of fast-flux service networks (FFSNs), a newly emerging and still not widely-known phenomenon in the Internet. FFSNs employ DNS to establish a proxy network on compromised machines through which illegal online services can be hosted with very high availability. Through our measurements we show that the threat which FFSNs pose is significant: FFSNs oc-cur on a worldwide scale and already host a substantial percentage of online scams. Based on analysis of the prin-ciples of FFSNs, we develop a metric with which FFSNs can be effectively detected. Considering our detection technique we also discuss possible mitigation strategies. 1

Key concepts: Computer science, The Internet, Metric (unit), Computer security, Proxy (statistics), Botnet, Empirical research, Service (business)

Related papers

Back to paper searchBrowse research topicsOriginal source
Measuring and Detecting Fast-Flux Service Networks — Research Paper | ScholarLens