A High Accuracy DNS Tunnel Detection Method Without Feature Engineering

Yang Chen, Xiaoyong Li
{"title":"A High Accuracy DNS Tunnel Detection Method Without Feature Engineering","authors":"Yang Chen, Xiaoyong Li","doi":"10.1109/CIS52066.2020.00086","DOIUrl":null,"url":null,"abstract":"Domain Name System (DNS) is a key protocol and service used on the Internet. It is responsible for converting domain names into IP addresses. DNS tunnel is a method of encoding data of other programs or protocols in DNS query and response. Previous studies usually need to extract a large number of features manually and train the classifier of DNS tunnel detection by feature engineering. In this paper, a new framework for DNS tunnel detection is proposed, which can automatically extract features, including long short-term memory (LSTM) language model with attention mechanism and gated recurrent unit (GRU) language model with attention mechanism. Finally, a single-level classifier based on a character-level convolutional neural network (Char-CNN) is proposed. The results show that the LSTM and GRU language models based on attention mechanism and the algorithm of character-level convolution neural network achieve high accuracy and near-zero false positives.","PeriodicalId":106959,"journal":{"name":"2020 16th International Conference on Computational Intelligence and Security (CIS)","volume":null,"pages":null},"PeriodicalIF":0.0000,"publicationDate":"2020-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"5","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 16th International Conference on Computational Intelligence and Security (CIS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CIS52066.2020.00086","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 5

Abstract

Domain Name System (DNS) is a key protocol and service used on the Internet. It is responsible for converting domain names into IP addresses. DNS tunnel is a method of encoding data of other programs or protocols in DNS query and response. Previous studies usually need to extract a large number of features manually and train the classifier of DNS tunnel detection by feature engineering. In this paper, a new framework for DNS tunnel detection is proposed, which can automatically extract features, including long short-term memory (LSTM) language model with attention mechanism and gated recurrent unit (GRU) language model with attention mechanism. Finally, a single-level classifier based on a character-level convolutional neural network (Char-CNN) is proposed. The results show that the LSTM and GRU language models based on attention mechanism and the algorithm of character-level convolution neural network achieve high accuracy and near-zero false positives.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
一种不需要特征工程的高精度DNS隧道检测方法
域名系统(DNS)是互联网上使用的关键协议和服务。它负责将域名转换为IP地址。DNS隧道是在DNS查询和响应中对其他程序或协议的数据进行编码的一种方法。以往的研究通常需要人工提取大量的特征,并通过特征工程训练分类器进行DNS隧道检测。本文提出了一种能够自动提取特征的DNS隧道检测框架,包括具有注意机制的长短期记忆(LSTM)语言模型和具有注意机制的门控循环单元(GRU)语言模型。最后,提出了基于字符级卷积神经网络(Char-CNN)的单级分类器。结果表明,基于注意机制的LSTM语言模型和基于字符级卷积神经网络的GRU语言模型均具有较高的准确率和接近于零的误报率。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Predicting Algorithms and Complexity in RNA Structure Based on BHG Efficient attribute reduction based on rough sets and differential evolution algorithm Numerical Analysis of Influence of Medicine Cover Structure on Cutting Depth [Copyright notice] Linear Elements Separation via Vision System Feature and Seed Spreading from Topographic Maps
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1