DNS Covert Channel Attack Detection Based on Spatio-Temporal Feature Fusion
Wei You, Chunlei Zhao, Chao Shan, Guozhong Dong, Jie Yu, Yong Guan · 2024
An increasing number of Advanced Persistent Threat (APT) organizations are utilizing DNS (Domain Name System) covert channels to evade network intrusion detection systems and establish private authoritative servers for remote attacks. However, current detection models for DNS covert channels often have poor performance and limited generalization ability. To address these challenges, we propose a DNS covert channel attack detection method based on spatiotemporal feature fusion. This method combines the Interaction timing sequence features of DNS traffic with the spatial statistical features of domain names, and constructs a detection model called ConvSLSTM, which integrates a Convolutional Neural Network (CNN) with a stacked Long Short Term Memory (LSTM) network. CNN extracts local spatial features from traffic, while stacked LSTM captures Interaction timing sequence features, significantly improving detection accuracy. This article uses three typical public datasets for experiments, which contain a total of 440000 DNS covert channel attack data. Comparative experiments show that our method is significantly superior to existing methods and exhibits stronger generalization ability in detecting DNS covert channel attacks constructed by unknown tools.