KRTunnel: DNS channel detector for mobile devices

被引:10
|
作者
Wang, Senmiao [1 ]
Sun, Luli [1 ]
Qin, Sujuan [1 ]
Li, WenMin [1 ]
Liu, Wentao [1 ]
机构
[1] Beijing Univ Posts & Telecommun, State Key Lab Networking & Switching Technol, Beijing 100876, Peoples R China
关键词
DNS tunnel detection; DNS response; Isolated forest; Android; Network security;
D O I
10.1016/j.cose.2022.102818
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Nowadays, DNS channel attacks on mobile devices have become a challenging threat. Attackers usually attack mobile devices and steal information with the help of DNS channel. It is difficult for users to de-tect this kind of attack, especially when attackers covert sensitive information in the DNS response. In this paper, we proposed a method for DNS tunnel detection based on isolated forest for Android. We constructed a framework for mobile devices to collect DNS tunnel traffic. Based on the analysis of DNS tunnel traffic generated on mobile devices, we extracted features based on DNS request and response and constructed the feature set. We proposed a DNS tunnel detector, KRTunnel, for mobile devices. Experi-ments showed that KRTunnel can identify unseen DNS tunnel traffic with the accuracy of 98.1%.(c) 2022 The Authors. Published by Elsevier Ltd. This is an open access article under the CC BY license ( http://creativecommons.org/licenses/by/4.0/ )
引用
收藏
页数:10
相关论文
共 50 条
  • [1] Prefetching of mobile devices information - a DNS perspective
    Bernard, Antoine
    Laroui, Mohammed
    Marot, Michel
    Balakrichenan, Sandoche
    Moungla, Hassine
    Ampeau, Benoit
    Afifi, Hossam
    Becker, Monique
    IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC 2022), 2022, : 4293 - 4299
  • [2] Flare-DNS Resolver (FDR) for optimizing DNS lookup overhead in mobile devices
    Ppallan, Jamsheed Manja
    Arunachalam, Karthikeyan
    Jaiswal, Sweta
    Sabareesh, Dronamraju Siva
    Seo, Sungki
    Kanagarathinam, Madhan Raj
    2019 16TH IEEE ANNUAL CONSUMER COMMUNICATIONS & NETWORKING CONFERENCE (CCNC), 2019,
  • [3] A Wideband Smart EMF Detector for Mobile Devices
    Tekin, Ahmet
    ELECTRICA, 2021, 21 (01): : 115 - 120
  • [4] BACKSCATTER AS A COVERT CHANNEL IN MOBILE DEVICES
    Yang, Zhice
    Huang, Qianyi
    Zhang, Qian
    GETMOBILE-MOBILE COMPUTING & COMMUNICATIONS REVIEW, 2018, 22 (01) : 31 - 34
  • [5] A simple ultrasonic Indoor/Outdoor detector for mobile devices
    Bisio, Igor
    Delfino, Alessandro
    Lavagetto, Fabio
    2015 INTERNATIONAL WIRELESS COMMUNICATIONS & MOBILE COMPUTING CONFERENCE (IWCMC), 2015, : 137 - 141
  • [6] NICScatter: Backscatter as a Covert Channel in Mobile Devices
    Yang, Zhice
    Huang, Qianyi
    Zhang, Qian
    PROCEEDINGS OF THE 23RD ANNUAL INTERNATIONAL CONFERENCE ON MOBILE COMPUTING AND NETWORKING (MOBICOM '17), 2017, : 356 - 367
  • [7] Blind multiuser detector over a mobile communication channel with ISI
    Kimura, Yuji
    Shibata, Koji
    Sakai, Takakazu
    Nakagaki, Atsushi
    2006 INTERNATIONAL SYMPOSIUM ON INTELLIGENT SIGNAL PROCESSING AND COMMUNICATIONS, VOLS 1 AND 2, 2006, : 469 - +
  • [8] Survey of DNS covert channel
    DNS隐蔽信道综述
    Cui, Xiang (cuixiang@gzhu.edu.cn), 1600, Editorial Board of Journal on Communications (42): : 164 - 178
  • [9] A Fast and Accurate Cascade Subspace Face/Eye Detector on Mobile Devices
    Ren, Jianfeng
    Jiang, Xudong
    Yuan, Junsong
    2011 IEEE INTERNATIONAL CONFERENCE ON COMPUTER VISION WORKSHOPS (ICCV WORKSHOPS), 2011,
  • [10] KRDroid: Ransomware-Oriented Detector for Mobile Devices Based on Behaviors
    Wang, Senmiao
    Qin, Sujuan
    Qin, Jiawei
    Zhang, Hua
    Tu, Tengfei
    Jin, Zhengping
    Guo, Jing
    APPLIED SCIENCES-BASEL, 2021, 11 (14):