Malicious DNS Tunnel Tool Recognition Using Persistent DoH Traffic Analysis

被引:7
|
作者
Mitsuhashi, Rikima [1 ,2 ]
Jin, Yong [3 ]
Iida, Katsuyoshi [2 ]
Shinagawa, Takahiro [4 ]
Takai, Yoshiaki [2 ]
机构
[1] Univ Tokyo, Informat Technol Ctr, Tokyo 1138658, Japan
[2] Hokkaido Univ, Informat Initiat Ctr, Sapporo 0600811, Japan
[3] Tokyo Inst Technol, Global Sci Informat & Comp Ctr, Tokyo 1528550, Japan
[4] Univ Tokyo, Informat Initiat Ctr, Tokyo 1138658, Japan
关键词
DNS over HTTPS (DoH); network traffic clas-sification; machine learning methods; gradient boosting decision tree algorithm; GBDT algorithm; suspicious DoH traffic; emerg-ing malicious DNS tunnel tool recognition; CIRA-CICDoHBrw-2020; DoH-Tunnel-Traffic-HKD;
D O I
10.1109/TNSM.2022.3215681
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
DNS over HTTPS (Do) can mitigate the risk of privacy breaches but makes it difficult to control network security services due to the DNS traffic encryption. However, since malicious DNS tunnel tools for the DoH protocol pose network security threats, network administrators need to recognize malicious communications even after the DNS traffic encryption has become widespread. In this paper, we propose a malicious DNS tunnel tool recognition system using persistent DoH traffic analysis based on machine learning. The proposed system can accomplish continuous knowledge updates for emerging malicious DNS tunnel tools on the machine learning model. The system is based on hierarchical machine learning classification and focuses on DoH traffic analysis. The evaluation results confirm that the proposed system is able to recognize the six malicious DNS tunnel tools in total, not only well-known ones, including dns2tcp, dnscat2, and iodine, but also the emerging ones such as dnstt, tcp-over-dns, and tuns with 98.02% classification accuracy.
引用
收藏
页码:2086 / 2095
页数:10
相关论文
共 50 条
  • [41] Demand Structure Analysis for Urban Traffic Using Automatic License Plate Recognition Data
    Hong, Rongrong
    Zhou, Dong
    An, Chengchuan
    Rao, Wenming
    Xia, Jingxin
    CICTP 2019: TRANSPORTATION IN CHINA-CONNECTING THE WORLD, 2019, : 5122 - 5134
  • [42] Comparison and analysis of road tunnel traffic accident frequencies and rates using random-parameter models
    Caliendo, Ciro
    De Guglielmo, Maria Luisa
    Guida, Maurizio
    JOURNAL OF TRANSPORTATION SAFETY & SECURITY, 2016, 8 (02) : 177 - 195
  • [43] Exposing the Rat in the Tunnel: Using Traffic Analysis for Tor-based Malware Detection<bold> </bold>
    Dodia, Priyanka
    AlSabah, Mashael
    Alrawi, Omar
    Wang, Tao
    PROCEEDINGS OF THE 2022 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, CCS 2022, 2022, : 875 - 889
  • [44] Anomaly-based model for detecting HTTP-tunnel traffic using network behavior analysis
    李世淙
    Yun Xiaochun
    Zhang Yongzheng
    High Technology Letters, 2014, 20 (01) : 63 - 69
  • [45] DETECTION OF TOOL WEAR USING GRADIENT ADAPTIVE LATTICE AND PATTERN-RECOGNITION ANALYSIS
    JIAA, CL
    DORNFELD, DA
    MECHANICAL SYSTEMS AND SIGNAL PROCESSING, 1992, 6 (02) : 97 - 120
  • [46] An automated tool for face recognition using visual attention and active shape models analysis
    Faro, A.
    Giordano, D.
    Spampinato, C.
    2006 28TH ANNUAL INTERNATIONAL CONFERENCE OF THE IEEE ENGINEERING IN MEDICINE AND BIOLOGY SOCIETY, VOLS 1-15, 2006, : 6001 - +
  • [47] Visual recognition for urban traffic data retrieval and analysis in major events using convolutional neural networks
    Yalong Pi
    Nick Duffield
    Amir H. Behzadan
    Tim Lomax
    Computational Urban Science, 2
  • [48] Visual recognition for urban traffic data retrieval and analysis in major events using convolutional neural networks
    Pi, Yalong
    Duffield, Nick
    Behzadan, Amir H.
    Lomax, Tim
    COMPUTATIONAL URBAN SCIENCE, 2022, 2 (01):
  • [49] Classification of Handwritten Devanagari Number - An analysis of Pattern Recognition Tool using Neural Network and CNN
    Prashanth, Duddela Sai
    Mehta, R. Vasanth Kumar
    Sharma, Nisha
    INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND DATA SCIENCE, 2020, 167 : 2445 - 2457
  • [50] Lithology and mineralogy recognition from geochemical logging tool data using multivariate statistical analysis
    Konate, Ahmed Amara
    Ma, Huolin
    Pan, Heping
    Qin, Zhen
    Ahmed, Hafizullah Abba
    Dembele, N'dji dit Jacques
    APPLIED RADIATION AND ISOTOPES, 2017, 128 : 55 - 67