40

DNS Tunneling: Threat Landscape and Improved Detection Solutions

Novruz Amirov
Baran Isik
Bilal Ihsan Tuncer
Serif Bahtiyar
Main:8 Pages
14 Figures
Bibliography:1 Pages
1 Tables
Abstract

Detecting Domain Name System (DNS) tunneling is a significant challenge in security due to its capacity to hide harmful actions within DNS traffic that appears to be normal and legitimate. Traditional detection methods are based on rule-based approaches or signature matching methods that are often insufficient to accurately identify such covert communication channels. This research is about effectively detecting DNS tunneling. We propose a novel approach to detect DNS tunneling with machine learning algorithms. We combine machine learning algorithms to analyze the traffic by using features extracted from DNS traffic. Analyses results show that the proposed approach is a good candidate to detect DNS tunneling accurately.

View on arXiv
Comments on this paper