Malicious DNS Tunnel Tool Recognition Using Persistent DoH Traffic Analysis

被引:7
|
作者
Mitsuhashi, Rikima [1 ,2 ]
Jin, Yong [3 ]
Iida, Katsuyoshi [2 ]
Shinagawa, Takahiro [4 ]
Takai, Yoshiaki [2 ]
机构
[1] Univ Tokyo, Informat Technol Ctr, Tokyo 1138658, Japan
[2] Hokkaido Univ, Informat Initiat Ctr, Sapporo 0600811, Japan
[3] Tokyo Inst Technol, Global Sci Informat & Comp Ctr, Tokyo 1528550, Japan
[4] Univ Tokyo, Informat Initiat Ctr, Tokyo 1138658, Japan
关键词
DNS over HTTPS (DoH); network traffic clas-sification; machine learning methods; gradient boosting decision tree algorithm; GBDT algorithm; suspicious DoH traffic; emerg-ing malicious DNS tunnel tool recognition; CIRA-CICDoHBrw-2020; DoH-Tunnel-Traffic-HKD;
D O I
10.1109/TNSM.2022.3215681
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
DNS over HTTPS (Do) can mitigate the risk of privacy breaches but makes it difficult to control network security services due to the DNS traffic encryption. However, since malicious DNS tunnel tools for the DoH protocol pose network security threats, network administrators need to recognize malicious communications even after the DNS traffic encryption has become widespread. In this paper, we propose a malicious DNS tunnel tool recognition system using persistent DoH traffic analysis based on machine learning. The proposed system can accomplish continuous knowledge updates for emerging malicious DNS tunnel tools on the machine learning model. The system is based on hierarchical machine learning classification and focuses on DoH traffic analysis. The evaluation results confirm that the proposed system is able to recognize the six malicious DNS tunnel tools in total, not only well-known ones, including dns2tcp, dnscat2, and iodine, but also the emerging ones such as dnstt, tcp-over-dns, and tuns with 98.02% classification accuracy.
引用
收藏
页码:2086 / 2095
页数:10
相关论文
共 50 条
  • [31] Traffic Sign Recognition using Blob Analysis and Template Matching
    Athrey, Kishan S.
    Kambalur, Bharat M.
    Kumar, Krishna K.
    6TH INTERNATIONAL CONFERENCE ON COMPUTER & COMMUNICATION TECHNOLOGY (ICCCT-2015), 2015, : 219 - 222
  • [32] Pedestrian Traffic Distribution Analysis Using Face Recognition Technology
    Miklasz, Marcin
    Olszewski, Piotr
    Nowosielski, Adam
    Kawka, Grzegorz
    ACTIVITIES OF TRANSPORT TELEMATICS, 2013, 395 : 303 - 312
  • [33] Using support vector machine in traffic analysis for website recognition
    Shi, JQ
    Fang, BX
    Bin, L
    Wang, FL
    PROCEEDINGS OF THE 2004 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-7, 2004, : 2680 - 2684
  • [34] IoT-KEEPER: Detecting Malicious IoT Network Activity Using Online Traffic Analysis at the Edge
    Hafeez, Ibbad
    Antikainen, Markku
    Ding, Aaron Yi
    Tarkoma, Sasu
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2020, 17 (01): : 45 - 59
  • [35] Automatic detection and recognition of traffic signs using geometric structure analysis
    Andrey, Vavilin
    Jo, Kang Hyun
    2006 SICE-ICASE INTERNATIONAL JOINT CONFERENCE, VOLS 1-13, 2006, : 5813 - +
  • [36] Using GIS as a tool to integrate land use, traffic analysis, and travel forecasting
    Hawkins, N.
    Smadi, O.
    Chai, X.
    Isebrands, H.
    EFFICIENT TRANSPORTATION AND PAVEMENT SYSTEMS: CHARACTERIZATION, MECHANISMS, SIMULATION, AND MODELING, 2009, : 89 - 96
  • [37] Automatic supervision of blanking tool wear using pattern recognition analysis
    Lee, WB
    Cheung, CF
    Chiu, WM
    Chan, LK
    INTERNATIONAL JOURNAL OF MACHINE TOOLS & MANUFACTURE, 1997, 37 (08): : 1079 - 1095
  • [38] A bridge dynamic response analysis and load recognition method using traffic imaging
    Tang, Liang
    Liu, Xiao-Bei
    Liu, Yi-Jun
    Yu, Kui
    Shen, Nan
    SCIENTIFIC REPORTS, 2024, 14 (01):
  • [39] A Resilience Analysis of a Motorway Tunnel Affected by a Traffic Accident Using the Average Vehicles' Speed as a Metric
    Caliendo, Ciro
    Russo, Isidoro
    Genovese, Gianluca
    INTERNATIONAL JOURNAL OF CIVIL ENGINEERING, 2024, 22 (04) : 505 - 522
  • [40] A Resilience Analysis of a Motorway Tunnel Affected by a Traffic Accident Using the Average Vehicles’ Speed as a Metric
    Ciro Caliendo
    Isidoro Russo
    Gianluca Genovese
    International Journal of Civil Engineering, 2024, 22 : 505 - 522