DNS hidden tunnel detection method and system
By constructing a DNS hidden tunnel detection model based on entropy value, multi-layer perceptron, word segmentation and Transformer encoder, the problems of poor detection reliability and low accuracy in the prior art are solved, and efficient identification of complex and new hidden tunnels is achieved.
Patent Information
- Application Number
- CN202510437159.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-09
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-04-09
AI Technical Summary
The existing DNS hidden tunnel detection technology has problems such as poor reliability and low accuracy, making it difficult to effectively identify new or complex hidden tunnels.
The detection model based on the entropy value scheme, multi-layer perceptron, word segmentation scheme and Transformer encoder is adopted. Through the steps of entropy value calculation, feature extraction, word segmentation and feature encoding, the training data set is constructed and model training is carried out to realize the detection of DNS hidden tunnels.
It improves the reliability and accuracy of DNS hidden tunnel detection, can effectively identify complex and new hidden tunnels, and reduces the false alarm rate.
Smart Images

Figure CN119939260A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of information technology security, and in particular relates to a DNS hidden tunnel detection method and system. Background Art
[0002] With the development of economy and technology and the improvement of people's living standards, the Internet has been widely used in people's production and life, bringing endless convenience to people's production and life. As the infrastructure of the Internet, the normal operation of DNS (Domain Name System) is crucial to the stability and reliability of the network.
[0003] However, DNS covert tunneling technology has been used by criminals as a means to bypass network security protection, steal sensitive information or conduct illegal activities. Therefore, the detection of DNS covert tunneling is of great significance to the Internet.
[0004] At present, the existing DNS covert tunnel detection technology has many shortcomings. Traditional detection methods mainly rely on simple rule matching or feature-based detection. These methods can often only detect some obvious and known tunnel patterns, and it is difficult to effectively identify new and complex covert tunnels. For example, rule-based detection methods require clear rules to be defined in advance, and these rules are difficult to cover all possible covert tunnel behaviors. Therefore, such solutions are easily bypassed by attackers and have poor reliability. In addition, although some machine learning-based methods have improved detection capabilities to a certain extent, such solutions still have problems with low accuracy and high false alarm rates. Summary of the invention
[0005] One of the purposes of the present invention is to provide a DNS covert tunnel detection method with high reliability and good accuracy.
[0006] A second object of the present invention is to provide a system for implementing the DNS covert tunnel detection method.
[0007] The DNS hidden tunnel detection method provided by the present invention comprises the following steps: S1. Obtain the existing DNS domain name dataset; S2. Preprocessing the DNS domain name dataset obtained in step S1 to construct a training dataset; S3. Based on the entropy scheme, multi-layer perceptron, word segmentation scheme and Transformer encoder, an initial model for DNS covert tunnel detection is constructed, which includes an entropy calculation module, a feature extraction module, a word segmentation module, a Transformer encoder module and a detection module; The entropy calculation module is used to calculate the entropy value of the input DNS domain name and upload the entropy data to the feature extraction module; the feature extraction module is used to extract the feature data of the input DNS domain name according to the entropy information; the word segmentation module is used to construct an index sequence for the input DNS domain name; the Transformer encoder module is used to fuse the feature data and index sequence of the input DNS domain name to achieve feature encoding; the detection module is used to fuse the feature encoding information and feature data and realize the detection of DNS covert tunnels; S4 using the training data set constructed in step S2, the DNS covert tunnel detection initial model constructed in step S3 is trained to obtain a DNS covert tunnel detection model; S5. Using the DNS covert tunnel detection model obtained in step S4, perform actual DNS covert tunnel detection.
[0008] The step S2 specifically includes the following steps: Performing data cleaning on the DNS domain name data in the DNS domain name data set obtained in step S1; Marking the DNS domain name data after data cleaning into categories; the categories include normal categories and abnormal categories; Finally, the training dataset is constructed.
[0009] The step S3 comprises the following steps: An entropy value calculation module is constructed based on the entropy value scheme to calculate the entropy value of the input DNS domain name; A number of multi-layer perceptrons connected in series are used as feature extraction modules to extract feature data of input DNS domain names according to entropy information; A word segmentation module is built based on the word segmenter to construct an index sequence for the input DNS domain name; A Transformer encoder module is constructed based on a bidirectional Transformer encoder and an expert mixture mechanism to fuse the feature data and index sequence of the input DNS domain name to achieve feature encoding; The softmax layer is used to build the detection module, which is used to fuse the feature encoding information and feature data, and output the probability of the category corresponding to the input DNS domain name.
[0010] The entropy value calculation module specifically includes the following contents: For the input DNS domain name, the corresponding entropy value H is calculated using the following formula: In the formula is the proportion of the iith character of the input DNS domain name that appears in the input DNS domain name; is the iith character of the entered DNS domain name; nn is the total length of the entered DNS domain name.
[0011] The feature extraction module specifically includes the following contents: For the input DNS domain name, obtain the corresponding entropy value H, and then count the length L of the domain name and the number of subdomains C to form the input vector Ln: ; The input vector Ln is input into a feature extraction module composed of several multi-layer perceptrons connected in series to obtain the extracted feature Out0.
[0012] The word segmentation module specifically includes the following contents: A tokenizer is used to analyze the input DNS domain name to construct a first index sequence In1 and a second index sequence In2; wherein, for the DNS domain name, the complete domain name is set as s2, and the part from the second-level domain name to the end of the domain name is s1. The tokenizer is used to tokenize s1 to obtain the first tokenization result tokens1, and s2 is used to tokenize to obtain the second tokenization result tokens2. Then, the tensor() method is used to construct the first index sequence In1 for tokens1, and the tensor() method is used to construct the second index sequence In2 for tokens2.
[0013] The Transformer encoder module specifically includes the following contents: The first index sequence In1 is mapped to the feature space through the embedding layer to obtain the first feature In1t; at the same time, the second index sequence In2 is mapped to the feature space through the embedding layer to obtain the second feature In2t; an expert mixture mechanism is added to the embedding layer to improve the generalization ability and performance of the model; The first feature In1t is linearly transformed and then input into the first bidirectional Transformer encoder for processing to obtain the first high-level feature Out1; After linear transformation of the second feature In2t, the first tag of the first high-level feature Out1 The stacked features In2ts are obtained by stacking, and the stacked features In2ts are then input into the second bidirectional Transformer encoder for processing to obtain the second high-level features Out2.
[0014] The detection module specifically includes the following contents: The first tag of feature Out0 and first high-level feature Out1 will be extracted and the first token of the second high-level feature Out2 After addition, the output distribution Out is obtained through the softmax layer processing; the output distribution Out corresponds to the probability of the category to which the input DNS domain name belongs.
[0015] The training described in step S4 specifically includes the following steps: The cross entropy loss function is used as the loss function of the training process; During training, the back-propagation algorithm is used to update the constructed model parameters according to the gradient of the loss function.
[0016] The present invention also provides a system for implementing the DNS hidden tunnel detection method, comprising a domain name acquisition module, a domain name processing module, a model construction module, a model training module and a domain name detection module; the domain name acquisition module, the domain name processing module, the model construction module, the model training module and the domain name detection module are connected in series in sequence; the domain name acquisition module is used to acquire an existing DNS domain name data set, and upload the data information to the domain name processing module; the domain name processing module is used to pre-process the acquired DNS domain name data set according to the received data information to construct a training data set, and upload the data information to the model construction module; the model construction module is used to construct a DNS hidden tunnel detection initial model including an entropy value calculation module, a feature extraction module, a word segmentation module, a Transformer encoder module and a detection module based on the received data information, and upload the data information to the model training module; wherein the entropy value calculation module is used to calculate the entropy value of the input DNS domain name, and upload the entropy value data to the feature extraction module; the feature extraction module is used to extract feature data of the input DNS domain name according to the entropy value information; the word segmentation module is used to construct an index sequence for the input DNS domain name; the Transformer The encoder module is used to fuse the feature data and index sequence of the input DNS domain name to realize feature encoding; the detection module is used to fuse the feature encoding information and the feature data, and realize the detection of the DNS covert tunnel; the model training module is used to train the constructed DNS covert tunnel detection initial model based on the received data information and the constructed training data set to obtain the DNS covert tunnel detection model, and upload the data information to the domain name detection module; the domain name detection module is used to perform actual DNS covert tunnel detection based on the received data information and the obtained DNS covert tunnel detection model.
[0017] The DNS hidden tunnel detection method and system provided by the present invention acquires and marks DNS domain name data, and constructs a DNS hidden tunnel detection model based on an entropy value scheme, a multi-layer perceptron, a word segmentation scheme, and a Transformer encoder, which not only realizes the detection of DNS hidden tunnels, but also ensures reliable detection results with high accuracy. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Figure 1 The figure is a schematic diagram of the method flow of the present invention.
[0019] Figure 2 Schematic diagram of the functional modules of the system of the present invention. DETAILED DESCRIPTION
[0020] like Figure 1 The method flow chart of the method of the present invention is shown as follows: The DNS hidden tunnel detection method disclosed in the present invention comprises the following steps: S1. Obtain the existing DNS domain name dataset.
[0021] S2. Preprocess the DNS domain name dataset obtained in step S1 to construct a training dataset; specifically, the steps include: Performing data cleaning on the DNS domain name data in the DNS domain name data set obtained in step S1; The DNS domain name data after data cleaning is categorized and marked; the categories include normal categories and abnormal categories (corresponding to domain names containing hidden tunnels); Finally, the training dataset is constructed.
[0022] S3. Based on the entropy scheme, multi-layer perceptron, word segmentation scheme and Transformer encoder, an initial model for DNS covert tunnel detection is constructed, which includes an entropy calculation module, a feature extraction module, a word segmentation module, a Transformer encoder module and a detection module; The entropy calculation module is used to calculate the entropy value of the input DNS domain name and upload the entropy data to the feature extraction module; the feature extraction module is used to extract the feature data of the input DNS domain name according to the entropy information; the word segmentation module is used to construct an index sequence for the input DNS domain name; the Transformer encoder module is used to fuse the feature data and index sequence of the input DNS domain name to realize feature encoding; the detection module is used to fuse the feature encoding information and feature data and realize the detection of DNS covert tunnels.
[0023] When implementing: An entropy calculation module is constructed based on the entropy solution to calculate the entropy value of the input DNS domain name; specifically, it includes the following contents: For the input DNS domain name, the corresponding entropy value H is calculated using the following formula: In the formula is the proportion of the iith character of the input DNS domain name that appears in the input DNS domain name; is the iith character of the input DNS domain name; nn is the total length of the input DNS domain name; in DNS tunnel detection, the entropy value of a normal domain name is relatively stable, while the entropy value of a domain name used for a covert tunnel is often high due to the encoding data and enhanced character randomness; therefore, comparing the entropy values can assist in determining whether a DNS tunnel exists.
[0024] Several multi-layer perceptrons connected in series are used as feature extraction modules to extract feature data of the input DNS domain name according to entropy information; specifically, the following contents are included: For the input DNS domain name, obtain the corresponding entropy value H, and then count the length L of the domain name and the number of subdomains C to form the input vector Ln: ; The input vector Ln is input into a feature extraction module composed of several multi-layer perceptrons connected in series to obtain the extracted feature Out0.
[0025] A word segmentation module is built based on the word segmenter to construct an index sequence for the input DNS domain name; specifically, it includes the following contents: A tokenizer is used to analyze the input DNS domain name to construct a first index sequence In1 and a second index sequence In2; wherein, for the DNS domain name, the complete domain name is set as s2, and the part from the second-level domain name to the end of the domain name is s1. The tokenizer is used to tokenize s1 to obtain the first tokenization result tokens1, and s2 is tokenized to obtain the second tokenization result tokens2. Then, the tensor() method is used to construct tokens1 to obtain the first index sequence In1, and the tensor() method is used to construct tokens2 to obtain the second index sequence In2. For example, taking the fifth-level domain name "sub1.sub2.sub3.example.com" as an example, the GPT-2 tokenizer is used to segment "example.com" and "sub1.sub2.sub3.example.com" respectively, and then the open source toolkit PyTorch is used to use the tensor() method on the segmentation results to construct the index sequences In1 and In2.
[0026] A Transformer encoder module is constructed based on a bidirectional Transformer encoder and an expert mixture mechanism to fuse the feature data and index sequence of the input DNS domain name to achieve feature encoding; specifically, the following contents are included: The first index sequence In1 is mapped to the feature space through the embedding layer to obtain the first feature In1t; at the same time, the second index sequence In2 is mapped to the feature space through the embedding layer to obtain the second feature In2t; an expert mixture mechanism is added to the embedding layer to improve the generalization ability and performance of the model; the expert mixture mechanism directly determines which expert model to use based on the actual domain name length and entropy, and activates the corresponding expert model if the input length and entropy reach a predefined threshold; the expert mixture mechanism can better adapt to different types of inputs through the combination of multiple expert models, thereby improving the generalization ability and performance of the model; The first feature In1t is linearly transformed and then input into the first bidirectional Transformer encoder for processing to obtain the first high-level feature Out1; After linear transformation of the second feature In2t, the first tag of the first high-level feature Out1 The stacked features In2ts are obtained by stacking. The stacked features In2ts are then input into the second bidirectional Transformer encoder for processing to obtain the second high-level features Out2. Transformer is a deep learning model based on the self-attention mechanism, which can effectively capture long-distance dependencies in sequences. The bidirectional Transformer can process sequences from both the forward and reverse directions at the same time, so as to better obtain contextual information. The advantages of the bidirectional Transformer encoder are as follows: First, it has a powerful feature extraction capability. Unlike traditional models that rely on manual features, it can automatically and deeply mine the rich features in DNS domain names, not only at the character level, but also at the word level and semantic level, thus providing a strong basis for accurately judging whether a DNS tunnel exists. Second, the bidirectional Transformer encoder can effectively handle long-distance dependencies through the self-attention mechanism, which is crucial for processing the complex association between characters and subdomains in the DNS query sequence. It can pay attention to each position of the sequence at the same time, accurately capture long-distance dependencies, greatly improve the ability to understand the domain name structure and semantics, and thus improve the detection accuracy. Third, the bidirectional Transformer encoder processes sequences from both the forward and reverse directions, which can obtain more comprehensive contextual information and avoid misjudgment due to local information. This comprehensive contextual understanding ability is particularly critical when judging whether a domain name is used for a covert tunnel.
[0027] The detection module is constructed using the softmax layer to fuse feature encoding information and feature data, and output the probability of the category corresponding to the input DNS domain name; specifically, it includes the following contents: The first tag of feature Out0 and first high-level feature Out1 will be extracted and the first token of the second high-level feature Out2 After addition, the output distribution Out is obtained through the softmax layer processing; the output distribution Out corresponds to the probability of the category to which the input DNS domain name belongs.
[0028] S4 using the training data set constructed in step S2, the DNS covert tunnel detection initial model constructed in step S3 is trained to obtain a DNS covert tunnel detection model; In the specific training process, the cross entropy loss function is used as the loss function of the training process; During training, the back-propagation algorithm is used to update the constructed model parameters according to the gradient of the loss function.
[0029] S5. Using the DNS covert tunnel detection model obtained in step S4, perform actual DNS covert tunnel detection.
[0030] The method of the present invention is further described below in conjunction with an embodiment: Two data sets are used to compare the method of the present invention with the existing solutions. The two data sets are GitHub data set and China Unicom data set CUT.
[0031] The GitHub dataset has 10,481 positive samples and 434 negative samples. The dataset is randomly divided into training, validation, and test sets in proportions to ensure that the ratio of positive and negative samples in all subsets remains consistent; each model is trained only on the training set and evaluated on the validation set, and the model with the best performance on the evaluation set is adopted on the test set.
[0032] The China Unicom dataset CUT is a dataset formed by collecting regular office network traffic data from the core switches of the provincial office network operated by China Unicom. The positive samples are domain names collected from regular office traffic and Alexa
[2020] TOP50000 domain names, while the negative samples are collected using tools such as DETQasim
[2018] , dns2tcpDembour and Collignon
[2017] , dnscat2Bowes
[2015] , DNSExfiltratorArno0x0x
[2018] , DNSliveryno0be
[2019] , iodineEkman
[2014] , and reverse DNS shellahhh
[2015] . The complete dataset includes 107,131 positive samples and 119,323 negative samples. The data is in The dataset is randomly split into training, validation, and test sets in proportions of , which ensures that the ratio of positive and negative samples remains consistent in all subsets; each model is trained only on the training set, evaluated on the validation set, and the model with the best performance on the evaluation set is adopted on the test set.
[0033] On the above two data sets, the method of the present invention and the existing scheme were experimented, and the evaluation indicators used included accuracy, recall, precision and F1 value. The specific data are shown in Table 1 and Table 2: Table 1 Schematic diagram of the comparison of evaluation indicators of experiments on the GitHub dataset
[0034] Table 2 Comparison of evaluation index data of experiments on China Unicom dataset CUT
[0035] Among them, the VM model was systematically explained by Vladimir Vapnik et al. in the book "The Nature of Statistical Learning Theory" in 1995; the CNN model was proposed by Yang Likun et al. in the paper "Gradient-Based Learning Applied to Document Recognition" in 1998; the LSTM model was proposed by SepP Hochreiter and Jürgen Schmidhuber in the paper "Long Short-Term Memory" in 1997; the simple model (directly using features) refers to a relatively simple and direct bidirectional transformer model, which directly takes all word-unit indexes of the domain name as input without adopting a complex hierarchical structure; the hierarchical model is the complete model proposed by the method of the present invention.
[0036] From Table 1 and Table 2, it can be seen that the solution proposed by the method of the present invention has achieved excellent results on both data sets, which illustrates the effectiveness and accuracy of the method of the present invention.
[0037] Then, different word segmenters and algorithm models are combined to conduct experiments on the China Unicom dataset. The experimental results are shown in Table 3: Table 3 Comparison of experimental evaluation index data of different word segmenters
[0038] From Table 3, we can see that the scheme of the present invention and the adopted GPT-2 word segmenter have the best comprehensive performance and have achieved excellent results in various indicators. This also illustrates the effectiveness and accuracy of the method of the present invention.
[0039] like Figure 2The functional module schematic diagram of the system of the present invention is shown as follows: the system for realizing the DNS hidden tunnel detection method disclosed in the present invention comprises a domain name acquisition module, a domain name processing module, a model construction module, a model training module and a domain name detection module; the domain name acquisition module, the domain name processing module, the model construction module, the model training module and the domain name detection module are connected in series in sequence; the domain name acquisition module is used to acquire an existing DNS domain name data set and upload the data information to the domain name processing module; the domain name processing module is used to pre-process the acquired DNS domain name data set according to the received data information to construct a training data set and upload the data information to the model construction module; the model construction module is used to construct a DNS hidden tunnel detection initial model including an entropy value calculation module, a feature extraction module, a word segmentation module, a Transformer encoder module and a detection module based on the received data information, based on the entropy value scheme, the multi-layer perceptron, the word segmentation scheme and the Transformer encoder, and upload the data information to the model training module; wherein the entropy value calculation module is used to calculate the entropy value of the input DNS domain name and upload the entropy value data to the feature extraction module; the feature extraction module is used to extract the feature data of the input DNS domain name according to the entropy value information; the word segmentation module is used to construct an index sequence for the input DNS domain name; the Transformer The encoder module is used to fuse the feature data and index sequence of the input DNS domain name to realize feature encoding; the detection module is used to fuse the feature encoding information and the feature data, and realize the detection of the DNS covert tunnel; the model training module is used to train the constructed DNS covert tunnel detection initial model based on the received data information and the constructed training data set to obtain the DNS covert tunnel detection model, and upload the data information to the domain name detection module; the domain name detection module is used to perform actual DNS covert tunnel detection based on the received data information and the obtained DNS covert tunnel detection model.
Claims
1. A DNS hidden tunnel detection method, characterized in that The steps include: S1. Obtain the existing DNS domain name dataset; S2. Preprocessing the DNS domain name dataset obtained in step S1 to construct a training dataset; S3. Based on the entropy scheme, multi-layer perceptron, word segmentation scheme and Transformer encoder, an initial model for DNS covert tunnel detection is constructed, which includes an entropy calculation module, a feature extraction module, a word segmentation module, a Transformer encoder module and a detection module; The entropy value calculation module is used to calculate the entropy value of the input DNS domain name and upload the entropy value data to the feature extraction module; The feature extraction module is used to extract the feature data of the input DNS domain name according to the entropy value information; the word segmentation module is used to construct an index sequence for the input DNS domain name; the Transformer encoder module is used to fuse the feature data and index sequence of the input DNS domain name to achieve feature encoding; the detection module is used to fuse the feature encoding information and feature data and realize the detection of DNS covert tunnels; S4 using the training data set constructed in step S2, the DNS covert tunnel detection initial model constructed in step S3 is trained to obtain a DNS covert tunnel detection model; S5. Using the DNS covert tunnel detection model obtained in step S4, perform actual DNS covert tunnel detection.
2. The DNS hidden tunnel detection method according to claim 1 is characterized in that The step S2 specifically includes the following steps: Performing data cleaning on the DNS domain name data in the DNS domain name data set obtained in step S1; Marking the DNS domain name data after data cleaning into categories; the categories include normal categories and abnormal categories; Finally, the training dataset is constructed.
3. The DNS hidden tunnel detection method according to claim 1 or 2, characterized in that The step S3 comprises the following steps: An entropy value calculation module is constructed based on the entropy value scheme to calculate the entropy value of the input DNS domain name; A number of multi-layer perceptrons connected in series are used as feature extraction modules to extract feature data of input DNS domain names according to entropy information; A word segmentation module is built based on the word segmenter to construct an index sequence for the input DNS domain name; A Transformer encoder module is constructed based on a bidirectional Transformer encoder and an expert mixture mechanism to fuse the feature data and index sequence of the input DNS domain name to achieve feature encoding; The softmax layer is used to build the detection module, which is used to fuse the feature encoding information and feature data, and output the probability of the category corresponding to the input DNS domain name.
4. The DNS hidden tunnel detection method according to claim 3 is characterized in that The entropy value calculation module specifically includes the following contents: For the input DNS domain name, the corresponding entropy value H is calculated using the following formula: In the formula is the proportion of the iith character of the input DNS domain name that appears in the input DNS domain name; is the iith character of the entered DNS domain name; nn is the total length of the entered DNS domain name.
5. The DNS hidden tunnel detection method according to claim 4 is characterized in that The feature extraction module specifically includes the following contents: For the input DNS domain name, obtain the corresponding entropy value H, and then count the length L of the domain name and the number of subdomains C to form the input vector Ln: ; The input vector Ln is input into a feature extraction module composed of several multi-layer perceptrons connected in series to obtain the extracted feature Out0.
6. The DNS hidden tunnel detection method according to claim 5 is characterized in that The word segmentation module specifically includes the following contents: A tokenizer is used to analyze the input DNS domain name to construct a first index sequence In1 and a second index sequence In2; wherein, for the DNS domain name, the complete domain name is set as s2, and the part from the second-level domain name to the end of the domain name is s1. The tokenizer is used to tokenize s1 to obtain the first tokenization result tokens1, and s2 is used to tokenize to obtain the second tokenization result tokens2. Then, the tensor() method is used to construct the first index sequence In1 for tokens1, and the tensor() method is used to construct the second index sequence In2 for tokens2.
7. The DNS hidden tunnel detection method according to claim 6, characterized in that The Transformer encoder module specifically includes the following contents: The first index sequence In1 is mapped to the feature space through the embedding layer to obtain the first feature In1t; at the same time, the second index sequence In2 is mapped to the feature space through the embedding layer to obtain the second feature In2t; an expert mixture mechanism is added to the embedding layer to improve the generalization ability and performance of the model; The first feature In1t is linearly transformed and then input into the first bidirectional Transformer encoder for processing to obtain the first high-level feature Out1; After linear transformation of the second feature In2t, the first tag of the first high-level feature Out1 Stacking is performed to obtain the stacking feature In2ts; The stacked feature In2ts is then input into the second bidirectional Transformer encoder for processing to obtain the second high-level feature Out2.
8. The DNS hidden tunnel detection method according to claim 7 is characterized in that The detection module specifically includes the following contents: The first tag of feature Out0 and first high-level feature Out1 will be extracted and the first token of the second high-level feature Out2 After addition, the output distribution Out is obtained through the softmax layer processing; the output distribution Out corresponds to the probability of the category to which the input DNS domain name belongs.
9. The DNS hidden tunnel detection method according to claim 1 or 2, characterized in that The training described in step S4 specifically includes the following steps: The cross entropy loss function is used as the loss function of the training process; During training, the back-propagation algorithm is used to update the constructed model parameters according to the gradient of the loss function.
10. A system for implementing the DNS covert tunnel detection method according to any one of claims 1 to 9, characterized in that It includes a domain name acquisition module, a domain name processing module, a model building module, a model training module and a domain name detection module; the domain name acquisition module, the domain name processing module, the model building module, the model training module and the domain name detection module are connected in series in sequence; the domain name acquisition module is used to obtain the existing DNS domain name data set and upload the data information to the domain name processing module; The domain name processing module is used to pre-process the acquired DNS domain name data set according to the received data information to construct a training data set, and upload the data information to the model construction module; The model building module is used to construct a DNS hidden tunnel detection initial model including an entropy calculation module, a feature extraction module, a word segmentation module, a Transformer encoder module and a detection module based on the received data information, based on the entropy scheme, the multi-layer perceptron, the word segmentation scheme and the Transformer encoder, and upload the data information to the model training module; wherein the entropy calculation module is used for the entropy value of the input DNS domain name, and the entropy value data is uploaded to the feature extraction module; the feature extraction module is used to extract the feature data of the input DNS domain name according to the entropy information; the word segmentation module is used to construct an index sequence for the input DNS domain name; the Transformer encoder module is used to fuse the feature data and index sequence of the input DNS domain name to realize feature encoding; the detection module is used to fuse the feature encoding information and the feature data, and realize the detection of the DNS hidden tunnel; the model training module is used to train the constructed DNS hidden tunnel detection initial model according to the received data information using the constructed training data set to obtain the DNS hidden tunnel detection model, and upload the data information to the domain name detection module; the domain name detection module is used to perform actual DNS hidden tunnel detection according to the received data information using the obtained DNS hidden tunnel detection model.
Citation Information
Patent Citations
Domain name information detection method and related device
CN112118205A
DNS hidden tunnel event automatic detection method and device, and electronic equipment
CN112822223A
Real-time DNS tunnel detection method based on programmable switch and related equipment
CN114844704A
DNS tunnel detection method based on fusion of coding features and statistical behavior features
CN115643087A
Concealed channel identification method and device, computer equipment and storage medium
CN116232673A