KRTunnel: DNS channel detector for mobile devices

Senmiao Wang,Luli Sun,Sujuan Qin,WenMin Li,Wentao Liu
DOI: https://doi.org/10.1016/j.cose.2022.102818
2022-09-01
Abstract:Nowadays, DNS channel attacks on mobile devices have become a challenging threat. Attackers usually attack mobile devices and steal information with the help of DNS channel. It is difficult for users to detect this kind of attack, especially when attackers covert sensitive information in the DNS response. In this paper, we proposed a method for DNS tunnel detection based on isolated forest for Android. We constructed a framework for mobile devices to collect DNS tunnel traffic. Based on the analysis of DNS tunnel traffic generated on mobile devices, we extracted features based on DNS request and response and constructed the feature set. We proposed a DNS tunnel detector, KRTunnel, for mobile devices. Experiments showed that KRTunnel can identify unseen DNS tunnel traffic with the accuracy of 98.1%.
computer science, information systems
What problem does this paper attempt to address?