A DNS Tunnel Sliding Window Differential Detection Method Based on Normal Distribution Reasonable Range Filtering

07/14/2022
by   Xin Ma, et al.
0

A covert attack method often used by APT organizations is the DNS tunnel, which is used to pass information by constructing C2 networks. And they often use the method of frequently changing domain names and server IP addresses to evade monitoring, which makes it extremely difficult to detect them. However, they carry DNS tunnel information traffic in normal DNS communication, which inevitably brings anomalies in some statistical characteristics of DNS traffic, so that it would provide security personnel with the opportunity to find them. Based on the above considerations, this paper studies the statistical discovery methodology of typical DNS tunnel high-frequency query behavior. Firstly, we analyze the distribution of the DNS domain name length and times and finds that the DNS domain name length and times follow the normal distribution law. Secondly, based on this distribution law, we propose a method for detecting and discovering high-frequency DNS query behaviors of non-single domain names based on the statistical rules of domain name length and frequency and we also give three theorems as theoretical support. Thirdly, we design a sliding window difference scheme based on the above method. Experimental results show that our method has a higher detection rate. At the same time, since our method does not need to construct a data set, it has better practicability in detecting unknown DNS tunnels. This also shows that our detection method based on mathematical models can effectively avoid the dilemma for machine learning methods that must have useful training data sets, and has strong practical significance.

READ FULL TEXT

page 1

page 11

research
06/01/2022

LDoS attack detection method based on traffic time-frequency characteristics

For the traditional denial-of-service attack detection methods have comp...
research
09/02/2019

Securing Big Data from Eavesdropping Attacks in SCADA/ICS Network Data Streams through Impulsive Statistical Fingerprinting

While data from Supervisory Control And Data Acquisition (SCADA) systems...
research
11/15/2022

Detecting Malicious Domains Using Statistical Internationalized Domain Name Features in Top Level Domains

The Domain Name System (DNS) is a core Internet service that translates ...
research
07/09/2020

Automatic Detection of Major Freeway Congestion Events Using Wireless Traffic Sensor Data: A Machine Learning Approach

Monitoring the dynamics of traffic in major corridors can provide invalu...
research
01/09/2014

Brazilian License Plate Detection Using Histogram of Oriented Gradients and Sliding Windows

Due to the increasingly need for automatic traffic monitoring, vehicle l...
research
05/20/2019

Adaptive DDoS attack detection method based on multiple-kernel learning

Distributed denial of service (DDoS) attacks have caused huge economic l...
research
07/25/2016

A Non-Parametric Control Chart For High Frequency Multivariate Data

Support Vector Data Description (SVDD) is a machine learning technique u...

Please sign up or login with your details

Forgot password? Click here to reset