Poster: DoHunter: A feature fusion-based LLM for DoH tunnel detection
Jiawen Diao, Shengmin Zhao, Jianguo Xie, Rongna Xie, Guozhen Shi · 2024
DNS over HTTPS (DoH) reduces the risk of privacy leakage of DNS queries, but it also provides a covert communication channel for malicious activities. In this paper, we propose a method for malicious encrypted traffic identification, which harnesses the advanced context comprehension of Large Language Model (LLM) and incorporates expert features to detect anomalies. The evaluation results show that the method proposed in this paper can not only identify common and emerging malicious DoH tunnel tools such as dns2tcp, iodine, and dnstt, but also identify weaponized DoH traffic within a real APT attack, with a recall of 0.9995.