CSR-PTDNG: A Graph Construction Method for DNS Tunneling Domain Names Detection

被引:0
|
作者
Xu, Zhaoyang [1 ,2 ]
Guan, Zhujie [1 ,2 ]
Tian, Mengmeng [1 ,2 ]
机构
[1] Southeast Univ, Sch Cyber Sci & Engn, Nanjing, Peoples R China
[2] Engn Res Ctr Blockchain Applicat Supervis & Manag, Nanjing, Peoples R China
基金
中国国家自然科学基金; 国家重点研发计划;
关键词
DNS tunnel; Network security; Graph Classification; GNN;
D O I
10.1109/ISCC61673.2024.10733579
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
DNS tunneling has led to significant privacy breaches and financial losses. Different tool for DNS tunneling serves varied purposes: penetration testing, firewall bypassing, and communication with C2 servers. Therefore, achieving multi-classification for different DNS tunneling software is crucial. However, previous research faced three issues: ineffective use of PDNS data, overlooking the topological relationships of entities, and not leveraging DNS tunnels' structural features, causing inefficiencies in multi-classification tasks. Our method utilizes the graph's powerful representation ability for relationship to exploit DNS tunnel domain names' structural features from PDNS data and to address sample imbalance meanwhile. We constructed a PDNS dataset containing 691,769 domain names and a graph dataset named CSR-PTDNG, comprising 41,943 graphs. The latter represents the first graph dataset related to DNS tunneling research. Besides, we adopt three encoders for Client, Subdomain, and Record data (Rdata) nodes. Using GNNs for node embeddings updating and graph classification, we evaluate the models and the framework in binary and multi-class tasks. Ultimately, all GNN models achieved nearly 1 AUC and F1-score, demonstrating the effectiveness of our graph construction approach.
引用
收藏
页数:7
相关论文
共 22 条
  • [21] A DGA domain names detection modeling method based on integrating an attention mechanism and deep neural network
    Fangli Ren
    Zhengwei Jiang
    Xuren Wang
    Jian Liu
    Cybersecurity, 3
  • [22] Deep graph convolutional network-based high-performance detection method for spectral domain gesture image stream
    Chen, Hong
    Geng, Qingjia
    Liu, Aiyong
    Zhao, Hongdong
    JOURNAL OF ELECTRONIC IMAGING, 2023, 32 (02)