浙江大学学报(工学版)  2017, Vol. 51 Issue (9): 1780-1787    DOI: 10.3785/j.issn.1008-973X.2017.09.012
罗友强1, 刘胜利1, 颜猛2, 武东英1
1. 数学工程与先进计算国家重点实验室, 河南 郑州 450001;
2. 西安报业传媒集团, 陕西 西安 710002
DNS tunnel Trojan detection method based on communication behavior analysis
LUO You-qiang1, LIU Sheng-li1, YAN Meng2, WU Dong-ying1
1. State Key Laboratory of Mathematical Engineering and Advanced Computing, Zhengzhou 450001, China;
2. Xi'an Newspaper Media Group, Xi'an 710002, China
The traditional DNS tunneling detection method based on load analysis and traffic monitoring has high false positive rate and can not effectively cope with the new DNS tunnel Trojan horse. Therefore, a DNS tunnel Trojan detection method based on communication behavior analysis was proposed. First, the difference between DNS tunnel Trojan communication behavior and normal DNS parsing behavior from the point of view of DNS sessions was analyzed. Second, seven features of DNS tunnel Trojan sessions were extracted, which composed DNS session evaluation vector. Then, DNS session evaluation vector classifiers using the random forest classification algorithm was approached; a DNS tunnel detection model based on communication behavior analysis was constructed. The experimental results show that this method not only has small false positive rate and low false negative rate, but also has high detection ability for unknown DNS tunnel Trojans.

收稿日期: 2016-11-18 出版日期: 2017-08-25
通讯作者: 刘胜利,男,教授     E-mail:
作者简介: 罗友强(1991-),男,硕士生,从事信息安全、网络对抗研究
罗友强, 刘胜利, 颜猛, 武东英. 基于通信行为分析的DNS隧道木马检测方法[J]. 浙江大学学报(工学版), 2017, 51(9): 1780-1787.

LUO You-qiang, LIU Sheng-li, YAN Meng, WU Dong-ying. DNS tunnel Trojan detection method based on communication behavior analysis. JOURNAL OF ZHEJIANG UNIVERSITY (ENGINEERING SCIENCE), 2017, 51(9): 1780-1787.


