Countering Malicious Processes with Process-DNS Association
Suphannee Sivakorn, Kangkook Jee, Yixin Sun, Lauri Korts-Pärn, Zhichun Li, Cristian Lumezanu, Zhenyu Wu, Lu-An Tang, Ding Li
Abstract
Modern malware and cyber attacks depend heavily on DNS services to make their campaigns reliable and difficult to track. Monitoring network DNS activities and blocking suspicious domains have been proven an effective technique in countering such attacks. However, recent successful campaigns reveal that attackers adapt by using seemingly benign domains and public web storage services to hide malicious activity. Also, the recent support for encrypted DNS queries provides attacker easier means to hide malicious traffic from network-based DNS monitoring.
We propose PDNS, an end-point DNS monitoring system based on DNS sensor deployed at each host in a network, along with a centralized backend analysis server. To detect such attacks, PDNS expands the monitored DNS activity context and examines process context which triggered that activity. Specifically, each deployed PDNS sensor matches domain name and the IP address related to the DNS query with process ID, binary signature, loaded DLLs, and code signing information of the program that initiated it. We evaluate PDNS on a DNS activity dataset collected from 126 enterprise hosts and with data from multiple malware sources. Using ML Classifiers including DNN, our results outperform most previous works with high detection accuracy: a true positive rate at 98.55% and a low false positive rate at 0.03%.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3886650f-626f-4dbe-b7af-151b1d14f1a8Cited by top-tier papers3
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- From WHOIS to WHOWAS: A Large-Scale Measurement Study of Domain Registration Privacy under the GDPRChaoyi Lu, Baojun Liu, Yiming Zhang, Zhou Li et al.NDSS 2021
- Back-Propagating System Dependency Impact for Attack InvestigationPengcheng Fang, Peng Gao, Changlin Liu, Erman Ayday et al.USENIX Security 2022
Builds on5
- A Comprehensive Measurement Study of Domain Generating MalwareDaniel Plohmann, Khaled Yakdan, Michael Klatt, Johannes Bader et al.USENIX Security 2016 · 252 citations
- Optimized Invariant Representation of Network Traffic for Detecting Unseen Malware VariantsKarel Bartos, Michal Sofka, Vojtech FrancUSENIX Security 2016 · 147 citations
- Investigating Commercial Pay-Per-Install and the Distribution of Unwanted SoftwareKurt Thomas, Juan A. Elices Crespo, Ryan Rasti, Jean-Michel Picod et al.USENIX Security 2016 · 77 citations
- Measuring PUP Prevalence and PUP Distribution through Pay-Per-Install ServicesPlaton Kotzias, Leyla Bilge, Juan CaballeroUSENIX Security 2016 · 74 citations
- Certified Malware: Measuring Breaches of Trust in the Windows Code-Signing PKIDoowon Kim, Bum Jun Kwon, Tudor DumitrasCCS 2017 · 64 citations
Related papers
- Encrypted DNS -> Privacy? A Traffic Analysis PerspectiveSandra Deepthy Siby, Marc Juarez, Claudia Díaz, Narseo Vallina-Rodriguez et al.NDSS 2020
- Practical Attacks Against DNS Reputation SystemsTillson Galloway, Kleanthis Karakolios, Zane Ma, Roberto Perdisci et al.S&P 2024 · 13 citations
- Resolution Without Dissent: In-Path Per-Query Sanitization to Defeat Surreptitious Communication Over DNSDaiping Liu, Ruian Duan, Jun WangS&P 2025
- Understanding the Implementation and Security Implications of Protective DNS ServicesMingxuan Liu, Yiming Zhang, Xiang Li, Chaoyi Lu et al.NDSS 2024
- RT-MD: Host-Centric Real-Time Detection of Multi-Domain DNS Data ExfiltrationPengfei Ren, Lutong Chen, Xuanbo Huang, Jiankang Sun et al.CCS 2026
