Visible to the public Biblio

Filters: Author is Buczak, Anna L.  [Clear All Filters]
2017-08-22
Buczak, Anna L., Hanke, Paul A., Cancro, George J., Toma, Michael K., Watkins, Lanier A., Chavis, Jeffrey S..  2016.  Detection of Tunnels in PCAP Data by Random Forests. Proceedings of the 11th Annual Cyber and Information Security Research Conference. :16:1–16:4.

This paper describes an approach for detecting the presence of domain name system (DNS) tunnels in network traffic. DNS tunneling is a common technique hackers use to establish command and control nodes and to exfiltrate data from networks. To generate the training data sufficient to build models to detect DNS tunneling activity, a penetration testing effort was employed. We extracted features from this data and trained random forest classifiers to distinguish normal DNS activity from tunneling activity. The classifiers successfully detected the presence of tunnels we trained on, and four other types of tunnels that were not a part of the training set.