首页> 外文期刊>ETRI journal >Refined identification of hybrid traffic in DNS tunnels based on regression analysis
【24h】

Refined identification of hybrid traffic in DNS tunnels based on regression analysis

机译:基于回归分析的DNS隧道中的混合流量的精制识别

获取原文
           

摘要

DNS (Domain Name System) tunnels almost obscure the true network?activities of users, which makes it challenging for the?gateway or censorship equipment to identify malicious or unpermitted?network?behaviors. An efficient way to address this problem is to conduct a?temporal‐spatial analysis on the tunnel traffic. Nevertheless, current studies on this topic limit the DNS tunnel to those with a single protocol, whereas more than one protocol may be used simultaneously. In this paper, we concentrate on the refined identification of two protocols mixed in a DNS tunnel. A feature set is first derived from DNS query and response flows, which is incorporated with deep neural networks to construct a regression model. We benchmark the proposed method with captured DNS tunnel traffic, the experimental results show that the proposed scheme can achieve identification accuracy of more than 90%. To the best of our knowledge, the proposed scheme is the first to estimate the ratios of two mixed protocols in DNS tunnels.
机译:DNS(域名系统)隧道几乎掩盖了真正的网络?用户的活动,这使得网关或审查设备挑战,以识别恶意或不合适的?网络?行为。解决这个问题的有效方法是对隧道流量进行时间空间分析。尽管如此,关于该主题的当前研究将DNS隧道限制为具有单个协议的DNS隧道,而可以同时使用多种协议。在本文中,我们专注于DNS隧道中混合的两种协议的精制识别。首先从DNS查询和响应流导出特征集,该响应流与深神经网络结合到构建回归模型。我们利用捕获的DNS隧道流量基准测试方法,实验结果表明,所提出的方案可以实现90%以上的识别准确性。据我们所知,所提出的计划是第一个估计DNS隧道中两个混合协议的比率。

著录项

获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号