Learning-Based Detection of Malicious Hosts by Analyzing Non-Existent DNS Responses

Jawad Ahmed, Hassan Habibi Gharakheili, Vijay Sivaraman · GLOBECOM 2022 - 2022 IEEE Global Communications Conference · 2022

DNS Water Torture attack is a type of DDoS attack on authoritative DNS servers and/or open resolvers, whereby the victim is bombarded with random non-existent domains (NXDs) DNS requests, exhausting their entire resources. A famous example of this attack was launched by Mirai botnet on Dyn DNS architecture in 2016. Researchers have proposed solutions to detect these attacks; however, they predominantly apply static thresholds to the count of NXD responses. This method can result in high false positives and needs to be customized to the traffic pattern of victim DNS servers, making it practically challenging for adoption at the source of potential attacks. This paper aims to detect possibly infected hosts of a university campus network that take part in this specific type of DNS-based attacks. Our contributions are threefold: (1) We analyze 120 days' worth of DNS traffic collected from the border of a large university campus network to draw insights into the characteristics of non-existent domain (NXD) responses from incoming DNS packets. We discuss how malicious NXDs differ from benign ones and highlight two attack scenarios based on their requested domain names; (2) We develop a method using multi-staged iForest models to detect malicious internal hosts based on the attributes of their DNS activity; (3) We evaluate the efficacy of our proposed method by applying it to live DNS data streams in our university campus network. We show how our models can detect infected hosts that generate high-volume and low-volume distributed non-existent DNS queries with more than 99% accuracy of correctly classifying legitimate hosts.

Read the paper · More papers on PaperTik