pith. sign in

arxiv: 1709.06363 · v1 · pith:4H32DHHCnew · submitted 2017-09-19 · 💻 cs.CR

Entropy-based Prediction of Network Protocols in the Forensic Analysis of DNS Tunnels

classification 💻 cs.CR
keywords networkanalysismethodtechniquestunnelingentropyforensicprediction
0
0 comments X
read the original abstract

DNS tunneling techniques are often used for malicious purposes but network security mechanisms have struggled to detect these. Network forensic analysis has thus been used but has proved slow and effort intensive as Network Forensics Analysis Tools struggle to deal with undocumented or new network tunneling techniques. In this paper we present a method to aid forensic analysis through automating the inference of protocols tunneled within DNS tunneling techniques. We analyze the internal packet structure of DNS tunneling techniques and characterize the information entropy of different network protocols and their DNS tunneled equivalents. From this, we present our protocol prediction method that uses entropy distribution averaging. Finally we apply our method on a dataset to measure its performance and show that it has a prediction accuracy of 75%. Our method also preserves privacy as it does not parse the actual tunneled content, rather it only calculates the information entropy.

This paper has not been read by Pith yet.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score.

  1. Identifying DNS-tunneled traffic with predictive models

    cs.CR 2019-06 unverdicted novelty 3.0

    Pairing DNS queries and responses in feature extraction raises MLP and Random Forest accuracy above 83% for detecting SSH/SFTP/Telnet tunnels, with roughly 95% reduction in data size.