DCC-Find: DNS Covert Channel Detection by Features Concatenation-Based LSTM

被引:0
|
作者
Han, Dongxu [1 ,2 ]
Dong, Pu [1 ]
Li, Ning [1 ]
Cui, Xiang [3 ]
Diao, Jiawen [4 ]
Wang, Qing [2 ]
Du, Dan [1 ]
Liu, Yuling [1 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing, Peoples R China
[2] Univ Chinese Acad Sci, Sch Cyber Secur, Beijing, Peoples R China
[3] Zhongguancun Lab, Beijing, Peoples R China
[4] Beijing Univ Posts & Telecommun Minis, Minist Educ, Key Lab Trustworthy Distributed Comp & Serv, Beijing, Peoples R China
关键词
DNS; covert channel detection; LSTM; features concatenation; DCC tools identification;
D O I
10.1109/TrustCom56396.2022.00050
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
DNS (Domain Name System) plays an important role in network communication and it is rarely blocked by firewalls and intrusion detection systems (IDS). It is a suitable way for attackers to build DCC (DNS Covert Channel), which is used for data exfiltration. In recent years, some DCC detection methods have been proposed based on deep learning and there is no need for manual feature extraction. However, some expert knowledge is helpful to express the DNS characteristic. In this paper, we propose a FC-LSTM (Features Concatenation-based LSTM) model to detect DCC. The statistical features are concatenated with the output features of the LSTM model. This method makes the expression of DNS domain names more abundant. The experimental results have shown that the DCC traffic can be identified from normal traffic via this model, and the recognition rate is significantly improved compared with the traditional LSTM model and CNN model. In addition, we implement multi-classification in terms of the DCC tools (some of them are used in APT32). We also add generalization DNS packets (simulating APT34 traffic using DCC for stealing and attacking) to verify the robustness of our model. The FC-LSTM model has a good detection performance as well.
引用
收藏
页码:307 / 314
页数:8
相关论文
共 50 条
  • [41] Detection of Human Bodies in Lying Position based on Aggregate Channel Features
    Sajat, Mohammad Aidil Shah
    Hashim, Habibah
    Tahir, Nooritawati Md
    2020 16TH IEEE INTERNATIONAL COLLOQUIUM ON SIGNAL PROCESSING & ITS APPLICATIONS (CSPA 2020), 2020, : 313 - 317
  • [42] PEDESTRIAN DETECTION VIA PCA FILTERS BASED CONVOLUTIONAL CHANNEL FEATURES
    Ke, Wei
    Zhang, Yao
    Wei, Pengxu
    Ye, Qixiang
    Jiao, Jianbin
    2015 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH, AND SIGNAL PROCESSING (ICASSP), 2015, : 1394 - 1398
  • [43] RETRACTED: Detection of Constellation-Modulated Wireless Covert Channel Based on Adjusted CNN Model (Retracted Article)
    Huang, Shuhua
    Liu, Weiwei
    Liu, Guangjie
    Dai, Yuewei
    Bai, Huiwen
    SECURITY AND COMMUNICATION NETWORKS, 2021, 2021
  • [44] Wireless Intrusion Detection of Covert Channel Attacks in ITU-T G.9959-Based Networks
    Fuller, Jonathan
    Ramsey, Benjamin
    Pecarina, John
    Rice, Mason
    PROCEEDINGS OF THE 11TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2016), 2016, : 137 - 145
  • [45] Skin Lesion Detection Using Hand-Crafted and DL-Based Features Fusion and LSTM
    Mahum, Rabbia
    Aladhadh, Suliman
    DIAGNOSTICS, 2022, 12 (12)
  • [46] Leveraging Byte-Level Features for LSTM-based Anomaly Detection in Controller Area Networks
    Liang, Lixue
    Lin, Xiaojie
    Ma, Baihe
    Wang, Xu
    He, Ying
    Liu, Ren Ping
    Ni, Wei
    2022 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM 2022), 2022, : 4903 - 4908
  • [47] Docked Ship Detection Based on Edge Line Analysis and Aggregation Channel Features
    Li Jingyuan
    Li Xiaorun
    Zhao Liaoying
    ACTA OPTICA SINICA, 2019, 39 (08)
  • [48] Real-Time Human Detection Based on Optimized Integrated Channel Features
    Shen, Jifeng
    Zuo, Xin
    Yang, Wankou
    Liu, Guohai
    PATTERN RECOGNITION (CCPR 2014), PT II, 2014, 484 : 286 - 295
  • [49] Docked Ship Detection Based on Edge Line Analysis and Aggregation Channel Features
    Li J.
    Li X.
    Zhao L.
    Guangxue Xuebao/Acta Optica Sinica, 2019, 39 (08):
  • [50] Multi-channel CNN-LSTM based Power System Event Classification via Wavelet Image Features
    Kim D.-I.
    Transactions of the Korean Institute of Electrical Engineers, 2023, 72 (09): : 982 - 986