Detecting DoH tunnels with privacy protection using federated learning

Bangling Li, Shen He, Huaxi Peng, Erpeng Zhang, Jun Xin · 2022

Domain Name System (DNS) service is a core service on the Internet and a key link to ensure the normal operation of the Internet. Since DNS can often pass through firewalls without being intercepted, it creates favorable conditions for attackers to build a covert channel based on the DNS protocol. DNS over HTTPS (DoH) can encrypt DNS lookup and response data packets to ensure that data packets are not monitored and used, but it also makes the DNS tunnels more difficult to detect. Due to the security of DoH, researchers began trying to detect DoH tunnels by using machine or deep learning. The effect of the model is not good if the data quality is poor or the amount of data is insufficient. Due to the privacy of traffic data, it is usually difficult to collect and share private traffic data to a centralized server. We propose a federated-learning DoH traffic classification framework (FL_DoH_CF), which permits multiple institutions to detect DoH tunnels by using convolutional neural network (CNN) without sharing traffic data. The experiments demonstrate that FL_DoH_CF is competitive with centralized learning, and it is still robust for non-independent and identically distributed (No_IID) data, and even achieves an accuracy of 99.86% for extreme one-class No_IID data.

Read the paper · More papers on PaperTik