A Byte-level CNN Method to Detect DNS Tunnels
Chang Liu, Liang Dai, Wenjing Cui, Tao Lin · 2019
DNS tunnel is a technology used to bypass firewalls for data exfiltration. It takes advantage of the characteristic of firewalls that always allow DNS traffic pass. Most of the studies have realized the detection of DNS tunnels from the perspective of traffic and payload. In recent years, due to the popularity of machine learning and data mining methods, researchers began trying to use them to detect DNS tunnels. However, these detection methods require a lot of professional knowledge to extract and construct feature set, and the detection results are often unsatisfactory. In order to solve the problem of manual feature extraction limitation and improve the detection accuracy of DNS tunnels, we propose a deep learning method, called Byte-level CNN, to detect the DNS tunnels in this paper. Furthermore, we propose to represent DNS packets with bytes for the first time, as the converted computable data to the CNN model. Compared with traditional machine learning methods, our byte-level CNN method can learn full information in the whole DNS packets, especially the sequential and structural information, besides common statistical information, and therefore achieves good performance results. The simulation showed that the detection accuracy and recall rate are significantly improved, and the complex manual feature extraction process is avoided as well.