Information-Based Heavy Hitters for Real-Time DNS Data Exfiltration Detection and Prevention

07/05/2023
by   Yarin Ozery, et al.
0

Data exfiltration over the DNS protocol and its detection have been researched extensively in recent years. Prior studies focused on offline detection methods, which although capable of detecting attacks, allow a large amount of data to be exfiltrated before the attack is detected and dealt with. In this paper, we introduce Information-based Heavy Hitters (ibHH), a real-time detection method which is based on live estimations of the amount of information transmitted to registered domains. ibHH uses constant-size memory and supports constant-time queries, which makes it suitable for deployment on recursive DNS servers to further reduce detection and response time. In our evaluation, we compared the performance of the proposed method to that of leading state-of-the-art DNS exfiltration detection methods on real-world datasets comprising over 250 billion DNS queries. The evaluation demonstrates ibHH's ability to successfully detect exfiltration rates as slow as 0.7B/s, with a false positive alert rate of less than 0.004, with significantly lower resource consumption compared to other methods.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
02/16/2023

Unsupervised Evaluation of Out-of-distribution Detection: A Data-centric Perspective

Out-of-distribution (OOD) detection methods assume that they have test g...
research
08/07/2023

Unsupervised Adversarial Detection without Extra Model: Training Loss Should Change

Adversarial robustness poses a critical challenge in the deployment of d...
research
11/27/2021

Distributed Anomaly Detection in Edge Streams using Frequency based Sketch Datastructures

Often logs hosted in large data centers represent network traffic data o...
research
03/21/2023

Real-Time Cyberattack Detection with Offline and Online Learning

This paper presents several novel algorithms for real-time cyberattack d...
research
12/16/2021

APTSHIELD: A Stable, Efficient and Real-time APT Detection System for Linux Hosts

Advanced Persistent Threat (APT) attack usually refers to the form of lo...
research
12/16/2021

Radio-Assisted Human Detection

In this paper, we propose a radio-assisted human detection framework by ...
research
08/29/2020

Puzzle-AE: Novelty Detection in Images through Solving Puzzles

Autoencoder (AE) has proved to be an effective framework for novelty det...

Please sign up or login with your details

Forgot password? Click here to reset