From Passive to Active: Near-optimal DNS-based Data Exfiltration Defense Method Based on Sticky Mechanism
Jiawen Diao, Binxing Fang, Xiang Cui, Zhongru Wang, Tian Wang, Shouyou Song · 2022
DNS-based data exfiltration has become increasingly popular among advanced persistent threat (APT) attackers owing to the ubiquity and penetrability of the DNS protocol. AI-powered methods solve the defect that attackers can easily bypass because of the fixed threshold and weight in rule matching while still suffer from several issues. Such as the lack of malware samples for training, the amplified impact of even low FPR present enormous obstacles to applying the model in real-world detection.We present a method to generate malicious traffic covering an extensive sample space based on Tactics, Techniques, and Procedures (TTPs). We then propose a sticky mechanism, which transforms certain decision-making into dynamic human-computer interaction decision-making, to verify the suspicious hosts recognized by the AI model. The experimental results demonstrate the superiority of our model by identifying eight kinds of real attacks precisely. The good performance on real-world traffic shows our method is a solid foothold for applying AI-powered detection to practical applications.