Skip to Main Content (Press Enter)

Logo CNR
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze

UNI-FIND
Logo CNR

|

UNI-FIND

cnr.it
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze
  1. Pubblicazioni

Unsupervised learning and rule extraction for Domain Name Server tunneling detection

Articolo
Data di Pubblicazione:
2019
Abstract:
The paper deals with k-means clustering and logic learning machine (LLM) for the detection of Domain Name Server (DNS) tunneling. As the LLM shows more versatility in rule generation and classification precision with respect to traditional decision trees, the approach reveals to be robust to a large set of system conditions. The detection algorithm is designed to be applied over streaming data, without accurate tuning of algorithms' parameters. An extensive performance evaluation is provided with respect to different tunneling tools and applications; silent intruders are considered. Results show robustness on a test set that exhibits a different behavior from training.
Tipologia CRIS:
01.01 Articolo in rivista
Keywords:
covert channel; rule extraction; unsupervised learning
Elenco autori:
Aiello, Maurizio; Mongelli, Maurizio; Muselli, Marco
Autori di Ateneo:
AIELLO MAURIZIO
MONGELLI MAURIZIO
MUSELLI MARCO
Link alla scheda completa:
https://iris.cnr.it/handle/20.500.14243/377367
Pubblicato in:
INTERNET TECHNOLOGY LETTERS
Journal
  • Utilizzo dei cookie

Realizzato con VIVO | Designed by Cineca | 26.5.0.0 | Sorgente dati: PREPROD (Ribaltamento disabilitato)