Information Based Heavy Hitters for Real-Time DNS Data Exfiltration Detection
Yarin Ozery, Asaf Nadler, Asaf Shabtai
摘要
Data exfiltration over the DNS protocol and its detection have been researched extensively in recent years. Prior studies focused on offline detection methods, which although capable of detecting attacks, allow a large amount of data to be exfiltrated before the attack is detected and dealt with. In this paper, we introduce Information-based Heavy Hitters (ibHH), a real-time detection method which is based on live estimations of the amount of information transmitted to registered domains. ibHH uses constant-size memory and supports constant-time queries, which makes it suitable for deployment on recursive DNS servers to further reduce detection and response time. In our evaluation, we compared the performance of the proposed method to that of leading state-of-the-art DNS exfiltration detection methods on real-world datasets comprising over 250 billion DNS queries. The evaluation demonstrates ibHH's ability to successfully detect exfiltration rates as slow as 0.7B/s, with a false positive alert rate of less than 0.004, with significantly lower resource consumption compared to other methods.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper2
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski 等NDSS 2019 · 被引用 826 次
- Akamai DNS: Providing Authoritative Answers to the World's QueriesKyle Schomp, Onkar Bhardwaj, Eymen Kurdoglu, Mashooq Muhaimen 等SIGCOMM 2020 · 被引用 38 次
相关 Paper
- RT-MD: Host-Centric Real-Time Detection of Multi-Domain DNS Data ExfiltrationPengfei Ren, Lutong Chen, Xuanbo Huang, Jiankang Sun 等CCS 2026
- Realtime Robust Malicious Traffic Detection via Frequency Domain AnalysisChuanpu Fu, Qi Li, Meng Shen, Ke XuCCS 2021 · 被引用 194 次
- Timely Reporting of Heavy Hitters using External MemoryPrashant Pandey, Shikha Singh, Michael A. Bender, Jonathan W. Berry 等SIGMOD 2020 · 被引用 15 次
- Continuous User Behavior Monitoring using DNS Cache Timing AttacksHannes Weissteiner, Roland Czerny, Simone Franza, Stefan Gast 等NDSS 2026 · 被引用 2 次
- Resolution Without Dissent: In-Path Per-Query Sanitization to Defeat Surreptitious Communication Over DNSDaiping Liu, Ruian Duan, Jun WangS&P 2025
