DNS Tunnel Detection Scheme Based on Machine Learning in Campus Network

2022 4th International Conference on Machine Learning, Big Data and Business Intelligence (MLBDBI)(2022)

引用 1|浏览1
暂无评分
摘要
DNS tunnel is a type of tunnel technique based on DNS protocol. It is usually used to establish C&C channel between the controlled host and master server in botnet by cybercriminals. This paper proposes a novel system to detect DNS tunnel intelligently. We first analyze domain characteristics from three aspects: payload-based features, traffic-based features, and resolution-based features, and then extract the representative features from the raw DNS servers in a real-world educational network. Finally, a fusion RF-LR model is proposed to classify the DNS tunnel, which first uses random forest as base learner and then takes leafnodes of each decision tree as input attributes of the logistic regression process. The experimental results demonstrate that our model is superior to other algorithms in terms of accuracy, recall and stability.
更多
查看译文
关键词
DNS tunnel,Domain-Flux,feature engineering,machine learning,random forest
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要