Detection of Malicious and Low Throughput Data Exfiltration Over the DNS Protocol

In the presence of security countermeasures, a malware designed for data\nexfiltration must do so using a covert channel to achieve its goal. Among\nexisting covert channels stands the domain name system (DNS) protocol. Although\nthe detection of covert channels over the DNS has been thoroughly studied in\nthe last decade, previous research dealt with a specific subclass of covert\nchannels, namely DNS tunneling. While the importance of tunneling detection is\nnot undermined, an entire class of low throughput DNS exfiltration malware\nremained overlooked. The goal of this study is to propose a method for\ndetecting both tunneling and low-throughput data exfiltration over the DNS.\nTowards this end, we propose a solution composed of a supervised feature\nselection method, and an interchangeable, and adjustable anomaly detection\nmodel trained on legitimate traffic. In the first step, a one-class classifier\nis applied for detecting domain-specific traffic that does not conform with the\nnormal behavior. Then, in the second step, in order to reduce the false\npositive rate resulting from the attempt to detect the low-throughput data\nexfiltration we apply a rule-based filter that filters data exchange over DNS\nused by legitimate services. Our solution was evaluated on a medium-scale\nrecursive DNS server logs, and involved more than 75,000 legitimate uses and\nalmost 2,000 attacks. Evaluation results shows that while DNS tunneling is\ncovered with at least 99% recall rate and less than 0.01% false positive rate,\nthe detection of low throughput exfiltration is more difficult. While not\npreventing it completely, our solution limits a malware attempting to avoid\ndetection with at most a 1kb/h of payload under the limitations of the DNS\nsyntax (equivalent to five credit cards details, or ten user credentials per\nhour) which reduces the effectiveness of the attack.\n

Paper

Similar papers

© 2026 NYSGPT2525 LLC