The Use of Beacon Signals to Detect Covert Channels in DNS Traffic
Mikhail Alekseevich Eremeev, Vladimir Sergeevich Nefedov, A. S. Ostrovskii, D. A. Semchenkov · Automatic Control and Computer Sciences · 2021
An approach to detect covert channels (C2-channels) based on the DNS protocol is considered. It involves identifying beacon signals or certain traffic signatures, which, in turn, are indicative of malware activity. An analysis of samples of real DNS traffic is carried out followed by approximation using a known statistical distribution. The time parameters of beacon signals sent at different frequencies are modeled and the optimal (according to the Neumann–Pearson criterion) detection threshold is determined. This threshold minimizes the probability to detect a false beacon signal. The results allow improving preliminary configuration of intrusion detection systems operating on a statistical approach to analyze network traffic parameters.