C2-DNSWatch: Endpoint Framework for Detecting Command and Control (C2) Connection of Advanced Persistent Threats (APTs)

Raja Zeeshan Haider, Baber Aslam, Haider Abdul Raheem Abbas, Zafar Iqbal · 2024

Advance Persistent Threats (APTs) are sophisti-cated cyber weapons for launching cyber offensive against adversaries. APTs implement state-of-the-art techniques and proceed in multiple stages to avoid detection. Apprehending APTs in developmental stages can lead to early discovery of attack. Command and Control (C2) connection is one of the essential stages of APTs and its timely discovery can lead to the detection of APTs. Most APTs employ Domain Name Service (DNS) as communication channels between attacker and victim. C2-DNSWatch, an endpoint framework has introduced an all-inclusive approach for detecting DNS-based C2 of APTs. It incorporates process-specific host-based features, correlated network activity, DNS metadata, DNS lexical analysis and threat intelligence from publicly available resources for detecting C2. Besides, it monitors the DNS link for probable data exfiltration. C2-DNSWatch has introduced many unique features, offering better performance and a high detection rate. C2-DNSWatch is an empirical framework for detecting C2 of APTs with an F1-Score of 98.70%.

Read the paper · More papers on PaperTik