Echoes From the Void: Detecting DNS Tunneling With Blackhole Features in Encrypted Scenarios With High Accuracy

计算机科学 空隙(复合材料) 加密 量子隧道 计算机网络 材料科学 物理 凝聚态物理 复合材料
作者
Wafa Alorainy
出处
期刊:IEEE Access [Institute of Electrical and Electronics Engineers]
卷期号:13: 138551-138567
标识
DOI:10.1109/access.2025.3595455
摘要

Domain name system (DNS) tunneling is a covert technique for data exfiltration and command-and-control communication, often bypassing traditional security mechanisms. It exploits the DNS, making it difficult to detect, especially when it uses encryption protocols such as DNS-over-HTTPS (DoH). This paper describes a novel detection framework analyzing client behavior towards simulated blackhole events that occur when a DNS query is dropped deliberately. The new approach introduces six new behavioral features concerning retry and domain-switching behavior in combination with eleven traditional DNS metrics. Experiments were conducted using the GraphTunnel data set (2,975,353 records) and the CIC-Bell-DNS-EXF-2021 (1,019,318 records). A five-fold cross-validation with a random forest classifier achieved 99.9% classification accuracy, a 99.9% F1 score, and 100% precision and recall. Feature importance analysis indicates that blackhole-related features contribute to the detection query-to-blackhole ratios (Gini importance of 0.35) and inter-blackhole intervals (0.20), which help focus on stealthy tunneling behavior. The system does not inspect the payload, so it works with a lightweight mechanism even under encrypted DNS traffic, enabling its real-time deployment. Apart from the computational capability, such a practical field deployment in commercial environments presents integration challenges. Integration within existing security information and event management (SIEM) systems or DNS infrastructures implies API compatibility, scaling for heterogeneous networks, and minimizing the disruption of established workflow. Enterprises also face limitations concerning regulatory compliance, data privacy, and operational costs in integrating new detection mechanisms. In order to address these issues, our system is designed modularly and protocol-independently so that it can be easily integrated with mainstream SIEM tools (i.e., Splunk, QRadar) and enterprise DNS resolvers using standard interfaces. Future end uses include validating the approach in live environments as a fast response to future evolutive threats such as wildcard DNS abuse and tunneling over amplified queries.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
KevinT应助科研通管家采纳,获得30
刚刚
Sylar发布了新的文献求助10
刚刚
66666666666666完成签到,获得积分10
刚刚
zyj完成签到,获得积分10
刚刚
隐形曼青应助科研通管家采纳,获得10
刚刚
积极向上的银杏完成签到,获得积分10
刚刚
ShawnJohn应助科研通管家采纳,获得10
刚刚
科研通AI6应助科研通管家采纳,获得10
刚刚
土木研学僧完成签到,获得积分10
1秒前
Vanilla应助科研通管家采纳,获得10
1秒前
Greg应助科研通管家采纳,获得10
1秒前
养头猪饿了吃完成签到,获得积分10
1秒前
zgrmws应助科研通管家采纳,获得10
1秒前
zgrmws应助科研通管家采纳,获得10
1秒前
雨姐科研应助科研通管家采纳,获得10
1秒前
科研通AI6应助科研通管家采纳,获得10
1秒前
雨姐科研应助科研通管家采纳,获得10
1秒前
科研通AI6应助科研通管家采纳,获得10
1秒前
Greg应助科研通管家采纳,获得10
2秒前
雨姐科研应助科研通管家采纳,获得10
2秒前
2秒前
任性的沅完成签到,获得积分10
2秒前
研友_VZG7GZ应助科研通管家采纳,获得30
2秒前
格兰德法泽尔完成签到,获得积分10
2秒前
雨姐科研应助科研通管家采纳,获得10
2秒前
kvvcp完成签到,获得积分10
2秒前
小二郎应助科研通管家采纳,获得10
2秒前
阔达萤完成签到 ,获得积分10
2秒前
satuo完成签到,获得积分10
2秒前
2秒前
LL完成签到,获得积分10
2秒前
RockRedfoo完成签到 ,获得积分10
3秒前
zbb123完成签到 ,获得积分10
3秒前
第七个太阳完成签到,获得积分10
3秒前
巧克力豆丁好好吃完成签到,获得积分10
3秒前
3秒前
合适尔蝶发布了新的文献求助10
4秒前
跳跃完成签到,获得积分10
4秒前
Doreen完成签到,获得积分10
5秒前
十一应助yKkkkkk采纳,获得50
6秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Clinical Microbiology Procedures Handbook, Multi-Volume, 5th Edition 2000
The Cambridge History of China: Volume 4, Sui and T'ang China, 589–906 AD, Part Two 1000
The Composition and Relative Chronology of Dynasties 16 and 17 in Egypt 1000
Russian Foreign Policy: Change and Continuity 800
Real World Research, 5th Edition 800
Qualitative Data Analysis with NVivo By Jenine Beekhuyzen, Pat Bazeley · 2024 800
热门求助领域 (近24小时)
化学 材料科学 生物 医学 工程类 计算机科学 有机化学 物理 生物化学 纳米技术 复合材料 内科学 化学工程 人工智能 催化作用 遗传学 数学 基因 量子力学 物理化学
热门帖子
关注 科研通微信公众号,转发送积分 5715880
求助须知:如何正确求助?哪些是违规求助? 5237687
关于积分的说明 15275397
捐赠科研通 4866497
什么是DOI,文献DOI怎么找? 2613022
邀请新用户注册赠送积分活动 1563137
关于科研通互助平台的介绍 1520689