Detection of Data Leakage Based on DNS Traffic

Siyu Zhang,Zhipeng Han,Kaida Jiang
DOI: https://doi.org/10.1109/ICPICS58376.2023.10235404
2023-01-01
Abstract:In recent years, malicious software that utilizes covert channels to transmit private data has become increasingly prevalent. The privacy information of affected users, such as accounts and passwords, is quietly transmitted to attackers. Hackers commonly employ covert tunnels that utilize the Domain Name System (DNS) to achieve this, transmitting stolen information through malicious domains. Traditional DNS tunneling techniques generate significant communication traffic, and related research has delved deeper into this area. However, they face challenges in detecting malicious software that transmits data at low rates. This paper proposes a DNS data leakage detection algorithm based on anomaly detection models. Through experimental verification combining simulated attacks with real data, this algorithm demonstrates high detection rates for low-rate data leakage channels, while also maintaining good detection performance for traditional DNS tunnels.
What problem does this paper attempt to address?