Detecting DNS Tunnelling and Data Exfiltration Using Dynamic Time Warping

Stefan Machmeier, Vincent Heuveline · 2024

Browsing the web relies on the Domain Name System (DNS) protocol. In short, it resolves domain names to addresses and manages zones of domain spaces in subtrees. With the rapid increase in security threats, malicious actors exploit such protocols to disguise activities and mislead security operators. In particular, attackers can communicate with compromised agents by hiding data in DNS requests and their impersonated authoritative name servers. This allows data extraction and execution of commands from Command & Control (C2) servers. Tracing such client communication reveals a continuous exchange of DNS packets; thus, various detection methods are applicable. In fact, this communication can be reformulated as an anomaly detection for time series. A promising yet undiscovered approach is the similarity comparison between benign and malicious DNS requests over time. We propose a detection method using k-Nearest-Neighbour (kNN) algorithm with Dynamic Time Warping (DTW) as distance metric. By this, we show that only a small subset of data is needed to achieve high discovery rates above 99.99% F1-Score. In addition, we cross-verified our method by inspecting production data provided by the computing centre of Heidelberg University. As a result, we achieved a False Discovery Rate (FDR) of 0.25%, showing high production usage potential.

Read the paper · More papers on PaperTik