Information Based Heavy Hitters for Real-Time DNS Data Exfiltration Detection
Yarin Ozery, Asaf Nadler, Asaf Shabtai
Abstract
Data exfiltration over the DNS protocol and its detection have been researched extensively in recent years. Prior studies focused on offline detection methods, which although capable of detecting attacks, allow a large amount of data to be exfiltrated before the attack is detected and dealt with. In this paper, we introduce Information-based Heavy Hitters (ibHH), a real-time detection method which is based on live estimations of the amount of information transmitted to registered domains. ibHH uses constant-size memory and supports constant-time queries, which makes it suitable for deployment on recursive DNS servers to further reduce detection and response time. In our evaluation, we compared the performance of the proposed method to that of leading state-of-the-art DNS exfiltration detection methods on real-world datasets comprising over 250 billion DNS queries. The evaluation demonstrates ibHH's ability to successfully detect exfiltration rates as slow as 0.7B/s, with a false positive alert rate of less than 0.004, with significantly lower resource consumption compared to other methods.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 56dce80f-f5be-41a3-978b-aa5b13737643Cited by top-tier papers1
Ask how each one uses itBuilds on2
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski et al.NDSS 2019 · 826 citations
- Akamai DNS: Providing Authoritative Answers to the World's QueriesKyle Schomp, Onkar Bhardwaj, Eymen Kurdoglu, Mashooq Muhaimen et al.SIGCOMM 2020 · 38 citations
Related papers
- RT-MD: Host-Centric Real-Time Detection of Multi-Domain DNS Data ExfiltrationPengfei Ren, Lutong Chen, Xuanbo Huang, Jiankang Sun et al.CCS 2026
- Realtime Robust Malicious Traffic Detection via Frequency Domain AnalysisChuanpu Fu, Qi Li, Meng Shen, Ke XuCCS 2021 · 194 citations
- Timely Reporting of Heavy Hitters using External MemoryPrashant Pandey, Shikha Singh, Michael A. Bender, Jonathan W. Berry et al.SIGMOD 2020 · 15 citations
- Continuous User Behavior Monitoring using DNS Cache Timing AttacksHannes Weissteiner, Roland Czerny, Simone Franza, Stefan Gast et al.NDSS 2026 · 2 citations
- Resolution Without Dissent: In-Path Per-Query Sanitization to Defeat Surreptitious Communication Over DNSDaiping Liu, Ruian Duan, Jun WangS&P 2025
