DNS Covert Channel Detection via Behavioral Analysis: a Machine Learning Approach

10/04/2020
by   Salvatore Saeli, et al.
0

Detecting covert channels among legitimate traffic represents a severe challenge due to the high heterogeneity of networks. Therefore, we propose an effective covert channel detection method, based on the analysis of DNS network data passively extracted from a network monitoring system. The framework is based on a machine learning module and on the extraction of specific anomaly indicators able to describe the problem at hand. The contribution of this paper is two-fold: (i) the machine learning models encompass network profiles tailored to the network users, and not to the single query events, hence allowing for the creation of behavioral profiles and spotting possible deviations from the normal baseline; (ii) models are created in an unsupervised mode, thus allowing for the identification of zero-days attacks and avoiding the requirement of signatures or heuristics for new variants. The proposed solution has been evaluated over a 15-day-long experimental session with the injection of traffic that covers the most relevant exfiltration and tunneling attacks: all the malicious variants were detected, while producing a low false-positive rate during the same period.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
08/19/2021

Network Security Modeling using NetFlow Data: Detecting Botnet attacks in IP Traffic

Cybersecurity, security monitoring of malicious events in IP traffic, is...
research
05/09/2019

Evaluation of Machine Learning Classifiers for Zero-Day Intrusion Detection -- An Analysis on CIC-AWS-2018 dataset

Detecting Zero-Day intrusions has been the goal of Cybersecurity, especi...
research
11/02/2018

An Anomaly-based Botnet Detection Approach for Identifying Stealthy Botnets

Botnets (networks of compromised computers) are often used for malicious...
research
04/17/2018

Fast Flux Detection via Data Mining on Passive DNS Traffic

In the last decade, the use of fast flux technique has become establishe...
research
06/27/2018

PIDS - A Behavioral Framework for Analysis and Detection of Network Printer Attacks

Nowadays, every organization might be attacked through its network print...
research
12/12/2020

Filtering DDoS Attacks from Unlabeled Network Traffic Data Using Online Deep Learning

DDoS attacks are simple, effective, and still pose a significant threat ...

Please sign up or login with your details

Forgot password? Click here to reset