Technique for Cyberattacks Detection Based on DNS Traffic Analysis

Sergii Lysenko, Kira Bobrovnikova, Олег Савенко, Roman Shchuka · 2020

Today, with the rapid spread of computer systems and information technology, as well as their integration into the global Internet, cyberattacks and malware are one of the main types of cybercrime. The damage they cause when they infect network hosts can range from a slight increase in outbound traffic to a complete network malfunction or loss of critical data. The paper presents a new technique for cyberattacks detection based on DNS traffic analysis. It ena- bles the proactive malicious requests detecting in corporate area networks based on DNS protocol, and is aimed to identify and block the malicious domains and DND data deletion requested by the attackers. The process of malicious requests detection is based on the use of "isolation forest" algorithm, which allows to detect the anomalies in DNS data exchange. Based on the general data deletion scheme, an anomaly of DNS traffic is ob- served when it is used for data exchange. The anomaly in the DNS traffic is detected due to analysis of the set of features concerning the requests and responses that may indicate the attack presence in the network.

Read the paper · More papers on PaperTik