Unveiling malicious DNS behavior profiling and generating benchmark dataset through application layer traffic analysis
MohammadMoein Shafi, Arash Habibi Lashkari, Hardhik Mohanty · Computers & Electrical Engineering · 2024
The Domain Name System (DNS) is a prime target for cyber attacks , necessitating the monitoring and analysis of DNS activities to detect malicious behaviors . This paper presents an innovative DNS behavioral profiling approach that addresses challenges posed by the dynamic landscape of cyber threats, encompassing issues like evasion tactics, content variability, discerning malicious intent , navigating URL obfuscation, low and slow tactics, and maintaining accuracy in the face of diverse normal behaviors, contributing to the advancement of robust threat detection. The framework leverages unique feature behaviors and correlations, incorporating a novel feature selection algorithm , pattern extraction methodology, and a robust neural network architecture for accurate profile construction. The research also includes the development of ALFlowLyzer, a custom application layer network flow analyzer, and introduces the BCCC-CIC-Bell-DNS-2024 dataset, addressing limitations in widely used public DNS datasets. Experimental results demonstrate the effectiveness of the proposed model in profiling various DNS activities.