DNSxD: Detecting Data Exfiltration Over DNS

DNSxD: Detecting Data Exfiltration Over DNS
复制标题

DNSxD:检测 DNS 上的数据泄露

DOI:
10.1109/nfv-sdn.2018.8725640
复制
发表时间:
2018
期刊:
2018 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)
影响因子:
--
通讯作者:
Sandra Scott
Sandra Scott
中科院分区:
--
文献类型:
--
作者:
Jacob Steadman;Sandra Scott

文献摘要

被引文献

相似文献

根据2017年SANS报告,每20个组织中就有1个成为数据泄露的受害者。数据泄露通常是网络攻击的最后阶段,对受害者组织造成破坏性后果。使用域名系统(DNS)协议进行数据泄露的问题最早是在1998年讨论的。二十年来,这种隐蔽的传输方法已经变得更加复杂,因为恶意行为者适应逃避检测技术。DNS用于数据泄露的流行是由于网络通信协议的本质。本文针对基于DNS的数据泄露问题,提出了一种利用软件定义网络(SDN)架构的检测和缓解方法。分析了当前流行的DNS数据泄漏攻击和泄漏检测机制,提出了一种用于DNS数据泄漏检测的特征集。DNSxD的应用程序,并与当前的泄漏检测机制相比,其性能进行了评估。
According to a 2017 SANS report, 1 in 20 organisations fall victim to data exfiltration. Data exfiltration, often the final stage of a cyber attack has damaging consequences for the victim organisation. The use of the Domain Name System (DNS) protocol for data exfiltration was first discussed in 1998. Twenty years on, this covert transmission method has become more sophisticated as malicious actors adapt to evade detection techniques. The popularity of DNS for data exfiltration is due to the essential nature of the protocol for network communication. This paper addresses the issue of DNS-based data exfiltration proposing a detection and mitigation method leveraging the Software-Defined Network (SDN) architecture. Popular DNS data exfiltration attacks and current exfiltration detection mechanisms are analysed to generate a feature-set for DNS data exfiltration detection. The DNSxD application is presented and its performance evaluated in comparison with the current exfiltration detection mechanisms.