Detection of Tunneling in DNS over HTTPS
Hrithik Jha, Iishi Patel, Gang Li, Aswani Kumar Cherukuri, I. Sumaiya Thaseen · 2021
Domain Name Service (DNS) enables users to query domain names which are then converted to IP addresses leading traffic to that specific website on the web. DNS over HTTPS (DoH) is a protocol for performing remote DNS resolution via the HTTP protocol. It enables increased user privacy and security by preventing eavesdropping and manipulation of DNS data by man-in-the-middle attacks. DoH helps keep the requests encrypted and minimizes the information exchanged during queries. Along with the added privacy and security advancements, DoH makes it harder to detect tunneling which can be used by malicious actors to transmit sensitive data out of the victim’s computer. DoH Tunneling enables these actors to insert malware or pass stolen information into DNS queries, creating a covert communication channel that bypasses most firewalls and results in sensitive data leakage. In this paper, we explore methods of data collection and detection of DoH tunneling using machine learning techniques based on the packet sizes and duration of requests.