Detecting and Identifying Low-Rate Data Exfiltration Over DNS Protocol
Akram Q. Algaolahi, Mohammed A. Makarem, Eshraqe A. E.Y. Alamri, Abdullah Al Hasan · 2025
Data exfiltration attacks increasingly exploit the Domain Name System (DNS) as a covert communication channel due to its ubiquitous presence and permissive firewall rules. While substantial attention has been given to detecting high-rate DNS tunneling attacks, low-rate DNS exfiltration, characterized by small, covert data packets intended to evade detection systems, remains inadequately addressed. This research proposes a deep learning-based detection framework specifically designed for identifying low-rate DNS exfiltration attacks. The proposed approach intentionally disregards traditional metrics related to traffic volume, timing, and data rate, instead leveraging novel feature extraction methods, such as subdomain depth analysis. Evaluation results demonstrate exceptional effectiveness, achieving accuracy, precision, recall, and F1-score of 99.83%, 99.73%, 99.94%, and 99.83% respectively, and a near-perfect ROC-AUC score, underscoring the proposed model’s strong capability in accurately classifying malicious DNS traffic.