首页 | 本学科首页   官方微博 | 高级检索  
     

基于流量切片的DNS隐蔽通道检测
引用本文:刘阳洋,阮树骅,曾雪梅. 基于流量切片的DNS隐蔽通道检测[J]. 计算机应用研究, 2023, 40(10): 3138-3143
作者姓名:刘阳洋  阮树骅  曾雪梅
作者单位:1. 四川大学网络空间安全学院;2. 四川大学网络空间安全研究院
基金项目:国家自然科学基金区域基金重点项目(U19A2081);;中央高校基础研究基金资助项目(2022SCU12116);
摘    要:针对DNS隐蔽信道(DCC)流量变形策略对现有检测方法的绕过性问题,提出了一种基于流量切片的DCC检测方法。该方法首先将实验环境出口流量基于滑动窗口分批,再基于主机端聚合形成流量切片,每个切片包含一个较短时间跨度中归属同一主机的DNS报文与Web报文,再对切片内DNS报文的数据量、请求行为、响应行为以及与Web报文的关联行为实施面向DCC检测的特征工程,并在此基础上建立DCC检测模型。对比实验表明,所构建的DCC检测模型在常规DCC流量切片集上检测准确性达到99.83%,误报率仅0.08%,在6类不同流量变形策略的变形DCC流量切片集上有平均95%以上的检出能力,远优于其他检测方案,证明了所提出的方法应对DCC流量变形的有效性。同时,该方法能在主机单个流量切片上对DCC通信作出有效检测,是一种具有良好实时性的检测方法。

关 键 词:DNS隐蔽通道  流量变形  主机流量切片  行为分析
收稿时间:2023-02-06
修稿时间:2023-09-10

DNS covert channel detection based on traffic slice
LIUYANGYANG,RUANSHUHUA and ZENGXUEMEI. DNS covert channel detection based on traffic slice[J]. Application Research of Computers, 2023, 40(10): 3138-3143
Authors:LIUYANGYANG  RUANSHUHUA  ZENGXUEMEI
Affiliation:Sichuan University,,
Abstract:In order to solve the problem of bypassing detection methods for DNS covert channel(DCC) traffic deformation strategies, this paper proposed a DCC detection method based on traffic slice. In this method, the traffic of the experimental environment was first divided into batches based on the sliding window, and then the traffic slice was obtained based on the aggregation of each host-end IP. Each slice contains DNS packets and Web packets belonging to the same host in a short time span. Then, for the DNS data volume, DNS request behavior, DNS response behavior, and association behavior correlation behavior with WEB of DNS in the slice implement DCC-detection-oriented feature engineering and create detection models on this basis. Comparative experiments show that the detection accuracy of the constructed DCC detection model on the conventional DCC traffic datasets is 99.83%, and the false positive rate is only 0.08%. On the deformed DCC traffic datasets with six types of different traffic deformation strategies, the detection ability of the DCC detection model is more than 95% on average, which is better than the other detection schemes. It proves that the proposed method is effective in dealing with DCC traffic deformation. Moreover, the proposed method, which can effectively detect DCC communication within a single traffic slice, is a detection method with good real-time performance.
Keywords:DNS covert channel   traffic deformation   host traffic slice   behavior analysis
点击此处可从《计算机应用研究》浏览原始摘要信息
点击此处可从《计算机应用研究》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号