DNS Tunnelling, Exfiltration and Detection over Cloud Environments

被引:4
|
作者
Salat, Lehel [1 ]
Davis, Mastaneh [1 ]
Khan, Nabeel [2 ]
机构
[1] Kingston Univ, Fac Engn Comp & Environm, Penrhyn Rd, Kingston Upon Thames KT1 2EE, England
[2] Univ Chester, Dept Comp Sci, Chester CH1 4BJ, England
关键词
DNS tunnelling; DNS exfiltration; the elastic stack; DNS monitoring; cloud computing; AWS; GCP; Iodine; DNScat2;
D O I
10.3390/s23052760
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
The domain name system (DNS) protocol is fundamental to the operation of the internet, however, in recent years various methodologies have been developed that enable DNS attacks on organisations. In the last few years, the increased use of cloud services by organisations has created further security challenges as cyber criminals use numerous methodologies to exploit cloud services, configurations and the DNS protocol. In this paper, two different DNS tunnelling methods, Iodine and DNScat, have been conducted in the cloud environment (Google and AWS) and positive results of exfiltration have been achieved under different firewall configurations. Detection of malicious use of DNS protocol can be a challenge for organisations with limited cybersecurity support and expertise. In this study, various DNS tunnelling detection techniques were utilised in a cloud environment to create an effective monitoring system with a reliable detection rate, low implementation cost, and ease of use for organisations with limited detection capabilities. The Elastic stack (an open-source framework) was used to configure a DNS monitoring system and to analyse the collected DNS logs. Furthermore, payload and traffic analysis techniques were implemented to identify different tunnelling methods. This cloud-based monitoring system offers various detection techniques that can be used for monitoring DNS activities of any network especially accessible to small organisations. Moreover, the Elastic stack is open-source and it has no limitation with regards to the data that can be uploaded daily.
引用
收藏
页数:18
相关论文
共 50 条
  • [21] Monitoring Enterprise DNS Queries for Detecting Data Exfiltration From Internal Hosts
    Ahmed, Jawad
    Gharakheili, Hassan Habibi
    Raza, Qasim
    Russell, Craig
    Sivaraman, Vijay
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2020, 17 (01): : 265 - 279
  • [22] DNS-IDS: Securing DNS in the Cloud Era
    Satam, Pratik
    Alipour, Hamid
    Al-Nashif, Youssif
    Hariri, Salim
    2015 INTERNATIONAL CONFERENCE ON CLOUD AND AUTONOMIC COMPUTING (ICCAC), 2015, : 296 - 301
  • [23] Detection of Exfiltration in Sewer Systems with Tracers
    Stegeman, Bram
    Langeveld, Jeroen
    Bogaard, Thom
    Clemens, Francois
    NEW TRENDS IN URBAN DRAINAGE MODELLING, UDM 2018, 2019, : 820 - 824
  • [24] DNS Over HTTPS Detection Using Standard Flow Telemetry
    Jerabek, Kamil
    Hynek, Karel
    Rysavy, Ondrej
    Burgetova, Ivana
    IEEE ACCESS, 2023, 11 : 50000 - 50012
  • [25] Stream-wise Detection of Surreptitious Traffic over DNS
    Cejka, Tomas
    Rosa, Zdenek
    Kubatova, Hana
    2014 IEEE 19TH INTERNATIONAL WORKSHOP ON COMPUTER AIDED MODELING AND DESIGN OF COMMUNICATION LINKS AND NETWORKS (CAMAD), 2014, : 300 - 304
  • [26] INTRUSION DETECTION TECHNIQUES PERFORMANCE IN CLOUD ENVIRONMENTS
    Sabahi, Farzad
    PROCEEDINGS OF THE 2011 3RD INTERNATIONAL CONFERENCE ON SOFTWARE TECHNOLOGY AND ENGINEERING (ICSTE 2011), 2011, : 431 - 435
  • [27] Scalable Object Detection for Edge Cloud Environments
    Hector, Rory
    Umar, Muhammad
    Mehmood, Asif
    Li, Zhu
    Bhattacharyya, Shuvra
    FRONTIERS IN SUSTAINABLE CITIES, 2021, 3
  • [28] Data Exfiltration: Methods and Detection Countermeasures
    King, James
    Bendiab, Gueltoum
    Savage, Nick
    Shiaeles, Stavros
    PROCEEDINGS OF THE 2021 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE (IEEE CSR), 2021, : 442 - 447
  • [29] On automatic cloud detection over ocean
    Kärner, O
    Di Girolamo, L
    INTERNATIONAL JOURNAL OF REMOTE SENSING, 2001, 22 (15) : 3047 - 3052
  • [30] An ensemble framework for detection of DNS-Over-HTTPS (DOH) traffic
    Aggarwal, Akarsh
    Kumar, Manoj
    MULTIMEDIA TOOLS AND APPLICATIONS, 2024, 83 (11) : 32945 - 32972