Detecting malicious DoH traffic: Leveraging small sample analysis and adversarial networks for detection

被引:0
|
作者
Wu, Shaoqian [1 ]
Wang, Wei [1 ]
Ding, Zhanmeng [1 ]
机构
[1] Beijing Topsec Network secur Technol Co LTD, Coordinate Lab, Beijing 100000, Peoples R China
关键词
DNS over HTTPS (DoH); Small sample; Limited data; Malicious detection; Generative adversarial networks; DNS;
D O I
10.1016/j.jisa.2024.103827
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In light of the escalating frequency of DNS attacks, it is imperative to bolster user security and privacy through the encryption of DNS queries. However, conventional methods for detecting DNS traffic are no longer effective in identifying encrypted traffic, particularly with the utilization of the DNS-over-HTTPS (DoH) protocol, which employs secure HTTPS for DNS resolution. To confront this challenge, we propose a novel model for detecting malicious DoH traffic, named DoH-TriCGAN, which distinguishes between non-DoH, benign DoH, and malicious DoH traffic. DoH-TriCGAN employs a conditional generative adversarial network comprising three network components, for which we only provide additional information to the generator. We extracted different small sample datasets and large sample dataset from the CIRA-CIC-DoHBrw-2020 dataset, to evaluate the efficiency and effectiveness of the proposed DoH-TriCGAN model, and compared the quality of the generated synthetic data. To establish a benchmark, we utilized the six metrics - accuracy, precision, recall, F1 -score, ROC_AUC, and PR_AUC - to assess the performance of our model. The results demonstrate our proposed model outperforms the other five models (RF, XGBoost, BiGRU, Autoencoder, Transformer), showing the best performance particularly in scenarios with limited training samples, while also demonstrating data expansion capabilities by generating high -quality synthetic data to address the issue of insufficient network traffic.
引用
收藏
页数:10
相关论文
共 50 条
  • [1] Real time detection of malicious DoH traffic using statistical analysis
    Moure-Garrido, Marta
    Campo, Celeste
    Garcia-Rubio, Carlos
    [J]. COMPUTER NETWORKS, 2023, 234
  • [2] Enhanced detection of imbalanced malicious network traffic with regularized Generative Adversarial Networks
    Chapaneri, Radhika
    Shah, Seema
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2022, 202
  • [3] Increasing Detection Rate for Imbalanced Malicious Traffic using Generative Adversarial Networks
    Memmesheimer, Pascal
    Machmeier, Stefan
    Heuveline, Vincent
    [J]. PROCEEDINGS OF THE 2024 EUROPEAN INTERDISCIPLINARY CYBERSECURITY CONFERENCE, EICC 2024, 2024, : 74 - 81
  • [4] Adversarial Malicious Encrypted Traffic Detection Based on Refined Session Analysis
    Li, Minghui
    Wu, Zhendong
    Chen, Keming
    Wang, Wenhai
    [J]. SYMMETRY-BASEL, 2022, 14 (11):
  • [5] Detecting Malicious Social Robots with Generative Adversarial Networks
    Wu, Bin
    Liu, Le
    Dai, Zhengge
    Wang, Xiujuan
    Zheng, Kangfeng
    [J]. KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2019, 13 (11): : 5594 - 5615
  • [6] Detection, characterization, and profiling DoH Malicious traffic using statistical pattern recognition
    Sepideh Niktabe
    Arash Habibi Lashkari
    Dilli Prasad Sharma
    [J]. International Journal of Information Security, 2024, 23 : 1293 - 1316
  • [7] Detection, characterization, and profiling DoH Malicious traffic using statistical pattern recognition
    Niktabe, Sepideh
    Lashkari, Arash Habibi
    Sharma, Dilli Prasad
    [J]. INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2024, 23 (02) : 1293 - 1316
  • [8] Malicious DNS Tunnel Tool Recognition Using Persistent DoH Traffic Analysis
    Mitsuhashi, Rikima
    Jin, Yong
    Iida, Katsuyoshi
    Shinagawa, Takahiro
    Takai, Yoshiaki
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2023, 20 (02): : 2086 - 2095
  • [9] Effective Malicious URL Detection by Using Generative Adversarial Networks
    Geng, Jinbu
    Li, Shuhao
    Liu, Zhicheng
    Cheng, Zhenyu
    Fan, Li
    [J]. WEB ENGINEERING (ICWE 2022), 2022, 13362 : 341 - 356
  • [10] Malicious Network Traffic Detection Based on Deep Neural Networks and Association Analysis
    Gao, Minghui
    Ma, Li
    Liu, Heng
    Zhang, Zhijun
    Ning, Zhiyan
    Xu, Jian
    [J]. SENSORS, 2020, 20 (05)