DNS exfiltration detection in the presence of adversarial attacks and modified exfiltrator behaviour

被引:0
|
作者
Kristijan Žiža
Predrag Tadić
Pavle Vuletić
机构
[1] University of Belgrade,
[2] School of Electrical Engineering,undefined
来源
International Journal of Information Security | 2023年 / 22卷
关键词
DNS exfiltration; Adversarial attacks; Machine learning;
D O I
暂无
中图分类号
学科分类号
摘要
The Domain Name System (DNS) exfiltration is an activity in which an infected device sends data to the attacker’s server by encoding it in DNS request messages. Because of the frequent use of DNS exfiltration for malicious purposes, exfiltration detection gained attention from the research community which proposed several predominantly machine learning-based methods. The majority of previous studies used publicly available DNS exfiltration tools with the default configuration parameters, resulting in datasets created from DNS exfiltration requests that are usually significantly longer, have more DNS name labels, and higher character entropy than average regular DNS requests. This further led to overly optimistic detection rates. In this paper, we have explored some of the strategies an attacker could use to avoid exfiltration detection. First, we have explored the impact of DNS exfiltration tools’ parameter variation on the exfiltration detection accuracy. Second, we have modified the DNSExfiltrator tool to produce exfiltration requests which have significantly lower character entropy. This approach proved to be capable of deceiving classifiers based on single DNS request features. Only around 1% of modified DNS requests shorter or equal to 9 bytes, and less than one third of DNS exfiltration requests in the overall population were accurately detected. In addition, we present a methodology and an aggregated feature set (including inter-request timing statistics) which can be used for accurate DNS exfiltration in this kind of adversarial settings.
引用
收藏
页码:1865 / 1880
页数:15
相关论文
共 50 条
  • [1] DNS exfiltration detection in the presence of adversarial attacks and modified exfiltrator behaviour
    Ziza, Kristijan
    Tadic, Predrag
    Vuletic, Pavle
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2023, 22 (06) : 1865 - 1880
  • [2] Adversarial Example Attacks and Defenses in DNS Data Exfiltration
    Savic, Izabela
    Yan, Haonan
    Lin, Xiaodong
    Gillis, Daniel
    EMERGING INFORMATION SECURITY AND APPLICATIONS, EISA 2023, 2024, 2004 : 147 - 163
  • [3] DNS Exfiltration Guided by Generative Adversarial Networks
    Fahim, Abdulrahman
    Zhu, Shitong
    Qian, Zhiyun
    Song, Chengyu
    Papalexakis, Evangelos
    Chakraborty, Supriyo
    Chan, Kevin
    Yu, Paul
    Jaeger, Trent
    Krishnamurthy, Srikanth, V
    9TH EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY, EUROS&P 2024, 2024, : 580 - 599
  • [4] Detection of Exfiltration and Tunneling over DNS
    Das, Anirban
    Shen, Min-Yi
    Shashanka, Madhu
    Wang, Jisheng
    2017 16TH IEEE INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND APPLICATIONS (ICMLA), 2017, : 737 - 742
  • [5] DNS Tunnelling, Exfiltration and Detection over Cloud Environments
    Salat, Lehel
    Davis, Mastaneh
    Khan, Nabeel
    SENSORS, 2023, 23 (05)
  • [6] Quickest Change Detection in the Presence of Transient Adversarial Attacks
    Vasantam, Thirupathaiah
    Towsley, Don
    Veeravalli, Venugopal V.
    2021 55TH ANNUAL CONFERENCE ON INFORMATION SCIENCES AND SYSTEMS (CISS), 2021,
  • [7] Improving DNS Data Exfiltration Detection Through Temporal Analysis
    Spathoulas, Georgios
    Anagnostopoulos, Marios
    Papageorgiou, Konstantinos
    Kavallieratos, Georgios
    Theodoridis, Georgios
    UBIQUITOUS SECURITY, UBISEC 2023, 2024, 2034 : 133 - 146
  • [8] Detection of malicious and low throughput data exfiltration over the DNS protocol
    Nadler, Asaf
    Aminov, Avi
    Shabtai, Asaf
    COMPUTERS & SECURITY, 2019, 80 : 36 - 53
  • [9] Learning-Based Robust Anomaly Detection in the Presence of Adversarial Attacks
    Zhong, Chen
    Gursoy, M. Cenk
    Velipasalar, Senem
    2022 IEEE WIRELESS COMMUNICATIONS AND NETWORKING CONFERENCE (WCNC), 2022, : 1206 - 1211
  • [10] Real-Time Detection of DNS Exfiltration and Tunneling from Enterprise Networks
    Ahmed, Jawad
    Gharakheili, Hassan Habibi
    Raza, Qasim
    Russell, Craig
    Sivaraman, Vijay
    2019 IFIP/IEEE SYMPOSIUM ON INTEGRATED NETWORK AND SERVICE MANAGEMENT (IM), 2019, : 649 - 653