Flow-based detection of DNS tunnels

  • Wendy Ellens
  • , Piotr Zuraniewski
  • , Harm Schotanus
  • , Anna Sperotto
  • , Michel Mandjes
  • , Erik Meeuwissen

Research output: Chapter in Book/Report/Conference proceedingConference contributionAcademicpeer-review

49 Citations (Scopus)
113 Downloads (Pure)

Abstract

DNS tunnels allow circumventing access and security policies in firewalled networks. Such a security breach can be misused for activities like free web browsing, but also for command & control traffic or cyber espionage, thus motivating the search for effective automated DNS tunnel detection techniques. In this paper we develop such a technique, based on the monitoring and analysis of network flows. Our methodology combines flow information with statistical methods for anomaly detection. The contribution of our paper is twofold. Firstly, based on flow-derived variables that we identified as indicative of DNS tunnelling activities, we identify and evaluate a set of non-parametrical statistical tests that are particularly useful in this context. Secondly, the efficacy of the resulting tests is demonstrated by extensive validation experiments in an operational environment, covering many different usage scenarios.
Original languageEnglish
Title of host publicationEmerging Management Mechanisms for the Future Internet
Subtitle of host publication7th IFIP WG 6.6 International Conference on Autonomous Infrastructure, Management, and Security, AIMS 2013, Barcelona, Spain, June 25-28, 2013, Proceedings
EditorsGuillaume Doyen, Martin Waldburger, Pavel Celeda, Anna Sperotto, Burkhard Stiller
Place of PublicationBerlin, Heidelberg
PublisherSpringer
Pages124-135
Number of pages12
ISBN (Electronic)978-3-642-38998-6
ISBN (Print)978-3-642-38997-9
DOIs
Publication statusPublished - Jun 2013
Event7th IFIP WG 6.6 International Conference on Autonomous Infrastructure, Management, and Security, AIMS 2013 - Barcelona, Spain
Duration: 25 Jun 201328 Jun 2013
Conference number: 7

Publication series

NameLecture Notes in Computer Science
PublisherSpringer Verlag
Volume7943
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference7th IFIP WG 6.6 International Conference on Autonomous Infrastructure, Management, and Security, AIMS 2013
Abbreviated titleAIMS 2013
Country/TerritorySpain
CityBarcelona
Period25/06/1328/06/13

Keywords

  • 2020 OA procedure

Fingerprint

Dive into the research topics of 'Flow-based detection of DNS tunnels'. Together they form a unique fingerprint.

Cite this