Detection of Communication Tunnels in Network Using DNS Logs
Sankalp Dogra, Manisha J. Nene · 2023
Domain Name Framework (DNS) assumes a significant part as an interpretation convention in ordinary utilization of the Web. The motivation behind DNS is to make an interpretation of space names into IP locations as well as the other way around. Its straightforward engineering can, without much of a stretch, be abused for pernicious exercises. One tremendous security danger concerning DNS is burrowing, which assists aggressors with bypassing the security frameworks inconspicuous. A DNS passage can be utilized for three purposes: as an order and control channel, for information exfiltration or in any event, for burrowing one more convention through it. In this paper, various procedures for DNS tunneling identification are overviewed. The research characterizes those originally founded on the kind of information and afterward inside the classifications of the sort of examination and finishes up with a correlation between the different identification procedures. Research also presents one genuine High level Persevering Danger crusade that uses DNS tunneling, and hypothetically analyse how well the overviewed identification strategies could distinguish it.