DNS tunnels detection via DNS-images

被引:21
作者
D'Angelo, Gianni [1 ]
Castiglione, Arcangelo [1 ]
Palmieri, Francesco [1 ]
机构
[1] Univ Salerno, Dept Comp Sci, Via Giovanni Paolo II 132, I-84084 Fisciano, SA, Italy
关键词
DNS security; DNS tunneling; Data exfiltration; Anomaly detection; Classification; Convolutional neural network;
D O I
10.1016/j.ipm.2022.102930
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
DNS tunneling is a typical attack adopted by cyber-criminals to compromise victims' devices,steal sensitive data, or perform fraudulent actions against third parties without their knowledge.The fraudulent traffic is encapsulated into DNS queries to evade intrusion detection. Unfortu-nately, traditional defense systems based on Deep Packet Inspection cannot always detect suchtraffic. As a result, DNS tunneling is one problem that has worried the cybersecurity communityover the past decade.In this paper, we propose a robust and reliable Deep Learning-based DNS tunneling detectionapproach to mine valuable insight from DNS query payloads. More precisely, several featuresare first extracted by the DNS flow, and then they are arranged as bi-dimensional images. AConvolutionalNeuralNetworkis used to automatically and adaptively learn spatial hierarchies offeatures to be used in a fully connected neural network for traffic classification. The proposedapproach may result in an extremely interesting task in predictive security approaches to attackdetection.The effectiveness of the proposal is evaluated in several experiments using a real-worldtraffic dataset. The obtained results show that our approach achieves 99.99% of accuracy andperforms better than state-of-the-art solutions
引用
收藏
页数:13
相关论文
共 49 条
[1]   DNS tunneling detection through statistical fingerprints of protocol messages and machine learning [J].
Aiello, M. ;
Mongelli, M. ;
Papaleo, G. .
INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2015, 28 (14) :1987-2002
[2]   Supervised Learning Approaches with Majority Voting for DNS Tunneling Detection [J].
Aiello, Maurizio ;
Mongelli, Maurizio ;
Papaleo, Gianluca .
INTERNATIONAL JOINT CONFERENCE SOCO'14-CISIS'14-ICEUTE'14, 2014, 299 :463-472
[3]   Performance assessment and analysis of DNS tunneling tools [J].
Aiello, Maurizio ;
Merlo, Alessio ;
Papaleo, Gianluca .
LOGIC JOURNAL OF THE IGPL, 2013, 21 (04) :592-602
[4]  
ALLARD F, 2011, J TELECOMMUN INF TEC, P37
[5]   DNS Tunneling Detection Method Based on Multilabel Support Vector Machine [J].
Almusawi, Ahmed ;
Amintoosi, Haleh .
SECURITY AND COMMUNICATION NETWORKS, 2018,
[6]  
[Anonymous], 2021, PCAPNG PCAP NEXT GEN
[7]  
Berg A., 2019, ARXIV190611246
[8]  
Born K., 2010, ARXIV10044358
[9]  
Buczak A. L., 2016, P 11 ANN CYB INF SEC
[10]  
Costa P.M., 2018, The Handbook of Histopathological Practices in Aquatic Environments, P1, DOI 10.1016/B978-0-12-810499-6.00001-2