期刊文献+

基于DoH流量的DGA识别方法 被引量:1

DGA Identification Method Based on DoH Traffic
下载PDF
导出
摘要 现有研究表明,域名生成算法(domain generation algorithm,DGA)已成为僵尸网络建立命令和控制服务通信的关键技术之一。由于利用DGA域名随机性的检测方法已趋于成熟,为逃避检测,DGA算法可能采用加密流量形式进行传输。针对基于域名随机性的检测模型缺乏对加密DGA流量的识别等问题,该文基于DoH(DNS-over-HTTPS)协议验证了DGA流量进行加密传输的可能性,分析了命令控制服务过程所产生的HTTP报文内容、HTTP流量及对应的TCP流量。因利用DoH协议进行传输的数据包中不再包含DNS报文解析过程,最终选取了DoH流量数据包的长度和时序信息等特征进行识别。在DoH网络中DGA流量特征分析的基础上结合KNN分类算法识别DGA域名,设计了一种基于特征工程与机器学习结合的识别方法,提供了DoH网络中DGA流量的检测方法。实验结果表明,基于DoH流量的DGA分类模型在人工数据集上的准确率达到了79%,表现出良好的分类精度,为DoH网络安全提供了保障。 Current research reveals that domain generation algorithm(DGA)has become one of the key technologies for Botnets to connect to C&C(command and control)servers.Since the detection method for the randomness of DGA domain name has become mature,the DGA algorithm may adopt the form of encrypted traffic transmission bypassing the detection mechanisms.In view of the lack of recognition of encrypted DGA traffic based on the randomness of the domain name detection model,we verify the possibility of encrypted transmission of DGA traffic based on the DoH(DNS-over-HTTPS)protocol,analyze HTTP message content,HTTP traffic and corresponding TCP traffic generated during the command and control server transmission process.Because the data packets transmission with the DoH protocol no longer contains the DNS message parsing process,the length and timing information of the DoH traffic data packets are finally selected for identification.Based on the analysis of DGA traffic characteristics in the DoH network,the KNN classification algorithm is used to identify DGA domain names,a recognition method based on the combination of feature engineering and machine learning is designed to provide a detection method for DGA traffic in the DoH network.Experiment shows that the accuracy of DGA recognition model based on DoH traffic on artificial data sets reaches 79%,showing ideal classification accuracy,which provides a guarantee for DoH network.
作者 张千帆 郭晓军 周鹏举 ZHANG Qian-fan;GUO Xiao-jun;ZHOU Peng-ju(School of Information Engineering,Xizang Minzu University,Xianyang 712000,China)
出处 《计算机技术与发展》 2021年第12期122-127,共6页 Computer Technology and Development
基金 西藏自治区自然科学基金项目(XZ2019ZRG-36(Z)) 西藏民族大学“藏秦喜马拉雅人才发展支持计划-杰出青年学者”项目(324011810216) 西藏民族大学“涉藏网络信息内容与数据安全团队”项目(324042000709)。
关键词 僵尸网络 命令控制服务 域名生成算法 DNS-over-HTTPS/DoH协议 网络流量分析 Botnet command&control/C&C server domain generation algorithm DNS-over-HTTPS/DoH protocol network traffic analysis
  • 相关文献

参考文献4

二级参考文献19

共引文献39

同被引文献5

引证文献1

二级引证文献3

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部