Skip to Main Content (Press Enter)

Logo CNR
  • ×
  • Home
  • People
  • Outputs
  • Organizations
  • Expertise & Skills

UNI-FIND
Logo CNR

|

UNI-FIND

cnr.it
  • ×
  • Home
  • People
  • Outputs
  • Organizations
  • Expertise & Skills
  1. Outputs

Profiling DNS tunneling attacks with PCA and mutual information

Academic Article
Publication Date:
2016
abstract:
The use of covert-channel methods to bypass security policies or leak sensitive data has increased in the last years. Malicious users neutralize security restriction through protocol encapsulation, tunneling peer-to-peer, chat, or HTTP packets into allowed protocols such as DNS or HTTP. In this article, we propose an innovative profiling system for DNS tunnels that is based on Principal Component Analysis and Mutual Information. Results from experiments conducted on a live network show that one of the introduced metric is able to characterize anomalies on small DNS servers, while the other behaves better on medium sized servers. Concerning DNS tunneling attacks, the proposed approach reveals to be an efficient tool for traffic profiling in the presence of DNS tunneling.
Iris type:
01.01 Articolo in rivista
Keywords:
Tunneling; covert channel; intrusion detection; ids; characterization; DNS protocol.
List of contributors:
Cambiaso, Enrico; Aiello, Maurizio; Mongelli, Maurizio; Papaleo, Gianluca
Authors of the University:
AIELLO MAURIZIO
CAMBIASO ENRICO
MONGELLI MAURIZIO
Handle:
https://iris.cnr.it/handle/20.500.14243/314004
Published in:
LOGIC JOURNAL OF THE IGPL (PRINT)
Journal
  • Overview

Overview

URL

http://jigpal.oxfordjournals.org/content/early/2016/09/13/jigpal.jzw056.full.pdf+html
  • Use of cookies

Powered by VIVO | Designed by Cineca | 26.5.0.0 | Sorgente dati: PREPROD (Ribaltamento disabilitato)