本文已被:浏览 8次 下载 80次
Received:May 17, 2024 Revised:June 12, 2024
Received:May 17, 2024 Revised:June 12, 2024
中文摘要: DNS作为互联网基础设施, 很少受到防火墙的深度监控, 导致黑客和APT组织通过DNS隐蔽隧道来窃取数据或控制网络, 对网络安全造成严重威胁. 针对现有检测方案容易被攻击者绕过以及泛化能力较弱的问题, 本研究改进了DNS流量的表征方法, 并提出了PFEC-Transformer (pcap features extraction CNN-Transformer)模型. 该模型以表征后的十进制数值序列作为输入, 在经过CNN模块进行局部特征提取后, 再通过Transformer分析局部特征间的长距离依赖模式并进行分类. 研究采集了互联网流量以及各类DNS隐蔽隧道工具生成的数据包构建数据集, 并使用包含未知隧道工具流量的公开数据集进行泛化能力测试. 实验结果表明, 该模型在测试数据集上取得了高达99.97%的准确率, 在泛化测试集上也达到了92.12%的准确率, 有效地证明了其在检测未知DNS隐蔽隧道方面的优异性能.
Abstract:As an Internet infrastructure, DNS is rarely subjected to deep monitoring by firewalls, allowing hackers and Asia-Pacific Telecommunity (APT) organizations to exploit DNS covert tunnels for data theft or network control and posing a significant threat to network security. In response to the easily bypassed nature of existing detection methods and their weak generalization capabilities, this study enhances the characterization method of DNS traffic and introduces the pcap features extraction CNN-Transformer (PFEC-Transformer) model. This model uses characterized decimal numerical sequences as input, conducts local feature extraction through CNN modules, and then analyzes long-distance dependency patterns between local features by using the Transformer for classification. The research builds datasets by collecting internet traffic and data packets generated by various DNS covert tunnel tools and conducts generalization testing with publicly available datasets containing traffic from unknown tunneling tools. Experimental results demonstrate that the model achieves an accuracy of 99.97% on the testing dataset and 92.12% on the generalization testing dataset, effectively showcasing its exceptional performance in detecting unknown DNS covert tunnels.
keywords: network security DNS covert tunnel anomaly traffic detection deep learning generalizability
文章编号: 中图分类号: 文献标志码:
基金项目:教育部科技发展中心-中国高校产学研创新基金新一代信息技术创新项目(2021ITA01009)
引用文本:
江魁,黄锐滨,邓昭蕊,伍波,朱思霖.基于PFEC-Transformer的DNS隐蔽隧道检测.计算机系统应用,,():1-12
JIANG Kui,HUANG Rui-Bin,DENG Zhao-Rui,WU Bo,ZHU Si-Lin.DNS Covert Tunnel Detection Based on PFEC-Transformer.COMPUTER SYSTEMS APPLICATIONS,,():1-12
江魁,黄锐滨,邓昭蕊,伍波,朱思霖.基于PFEC-Transformer的DNS隐蔽隧道检测.计算机系统应用,,():1-12
JIANG Kui,HUANG Rui-Bin,DENG Zhao-Rui,WU Bo,ZHU Si-Lin.DNS Covert Tunnel Detection Based on PFEC-Transformer.COMPUTER SYSTEMS APPLICATIONS,,():1-12