DNS Covert Tunnel Detection Method and System
By constructing a DNS hidden tunnel detection model based on entropy value, multi-layer perceptron, word segmentation and Transformer encoder, the problem of low detection reliability and accuracy in the prior art is solved, and efficient identification of complex and new hidden tunnels is achieved.
Patent Information
- Application Number
- CN202510437159.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-09
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2045-04-09
AI Technical Summary
The existing DNS hidden tunnel detection technology has problems such as poor reliability and low accuracy, making it difficult to effectively identify new or complex hidden tunnels.
The detection method based on the entropy value scheme, multi-layer perceptron, word segmentation scheme and Transformer encoder is adopted to construct a DNS hidden tunnel detection model including entropy value calculation module, feature extraction module, word segmentation module, Transformer encoder module and detection module. The detection of hidden tunnels is realized through preprocessing and feature encoding of DNS domain name data.
It improves the reliability and accuracy of DNS hidden tunnel detection, can effectively identify complex and new hidden tunnels, and reduces the false alarm rate.
Smart Images

Figure CN119939260B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of information technology security, and particularly relates to a DNS covert tunnel detection method and system. Background Art
[0002] With the development of economy and technology and the improvement of people's living standards, the Internet has been widely applied in people's production and life, bringing endless convenience to people's production and life. As the infrastructure of the Internet, the normal operation of DNS (Domain Name System) is crucial for the stability and reliability of the network.
[0003] However, the DNS covert tunnel technology has been exploited by criminals and has become a means to bypass network security protection, steal sensitive information or conduct illegal activities. Therefore, the detection of DNS covert tunnels is of great significance to the Internet.
[0004] Currently, there are many deficiencies in the existing DNS covert tunnel detection technologies. Traditional detection methods mainly rely on simple rule matching or feature-based detection. These methods can often only detect some obvious and known tunnel patterns and are difficult to effectively identify new and complex covert tunnels. For example, rule-based detection methods need to define clear rules in advance, and these rules are difficult to cover all possible covert tunnel behaviors. Therefore, such solutions are easily bypassed by attackers and their reliability is poor. In addition, although some machine learning-based methods have improved the detection ability to a certain extent, such solutions still have problems of low accuracy and high false alarm rate. Summary of the Invention
[0005] One object of the present invention is to provide a DNS covert tunnel detection method with high reliability and good accuracy.
[0006] Another object of the present invention is to provide a system for implementing the DNS covert tunnel detection method.
[0007] The DNS covert tunnel detection method provided by the present invention includes the following steps:
[0008] S1. Obtain the existing DNS domain name dataset;
[0009] S2. Preprocess the DNS domain name dataset obtained in step S1 to construct a training dataset;
[0010] S3. Based on the entropy value scheme, multi-layer perceptron, word segmentation scheme and Transformer encoder, construct a DNS covert tunnel detection initial model including an entropy value calculation module, a feature extraction module, a word segmentation module, a Transformer encoder module and a detection module;
[0011] The entropy value calculation module is used to calculate the entropy value of the input DNS domain name and upload the entropy value data to the feature extraction module; the feature extraction module is used to extract the feature data of the input DNS domain name according to the entropy value information; the word segmentation module is used to construct an index sequence for the input DNS domain name; the Transformer encoder module is used to fuse the feature data and the index sequence of the input DNS domain name to achieve feature encoding; the detection module is used to fuse the feature encoding information and the feature data and detect the DNS covert tunnel.
[0012] S4. Use the training data set constructed in step S2 to train the initial DNS covert tunnel detection model constructed in step S3 to obtain a DNS covert tunnel detection model.
[0013] S5. Use the DNS covert tunnel detection model obtained in step S4 to perform actual detection of DNS covert tunnels.
[0014] The said step S2 specifically includes the following steps:
[0015] Perform data cleaning on the DNS domain name data in the DNS domain name data set obtained in step S1.
[0016] Perform category marking on the DNS domain name data after data cleaning; the said categories include normal category and abnormal category.
[0017] Finally, construct a training data set.
[0018] The said step S3 includes the following steps:
[0019] Construct an entropy value calculation module based on the entropy value scheme to calculate the entropy value of the input DNS domain name.
[0020] Use several cascaded multi-layer perceptrons as the feature extraction module to extract the feature data of the input DNS domain name according to the entropy value information.
[0021] Construct a word segmentation module based on a tokenizer to construct an index sequence for the input DNS domain name.
[0022] Construct a Transformer encoder module based on a bidirectional Transformer encoder and an expert mixture mechanism to fuse the feature data and the index sequence of the input DNS domain name to achieve feature encoding.
[0023] Use a softmax layer to construct a detection module to fuse the feature encoding information and the feature data and output the probability of the category corresponding to the input DNS domain name.
[0024] The said entropy value calculation module specifically includes the following content:
[0025] For the input DNS domain name, the corresponding entropy value H is calculated using the following formula: In the formula is the proportion of the i-th character in the input DNS domain name that appears in the input DNS domain name; is the i-th character of the input DNS domain name; n is the total length of the input DNS domain name.
[0026] The feature extraction module specifically includes the following content:
[0027] For the input DNS domain name, obtain the corresponding entropy value H, and then count the length L of the domain name and the number C of sub-domains to form the input vector Ln as ;
[0028] Input the input vector Ln into the feature extraction module composed of several cascaded multi-layer perceptrons to obtain the extracted feature Out0.
[0029] The word segmentation module specifically includes the following content:
[0030] Use a word segmenter to analyze the input DNS domain name to construct the first index sequence In1 and the second index sequence In2; among them, for the DNS domain name, set the full domain name as s2, and the part from the second-level domain name to the end of the domain name as s1. Use the word segmentation tool to segment s1 to obtain the first word segmentation result tokens1, segment s2 to obtain the second word segmentation result tokens2, and then use the tensor() method to construct the first index sequence In1 from tokens1 and the second index sequence In2 from tokens2.
[0031] The Transformer encoder module specifically includes the following content:
[0032] Map the first index sequence In1 to the feature space through the embedding layer to obtain the first feature In1t; at the same time, map the second index sequence In2 to the feature space through the embedding layer to obtain the second feature In2t; add a mixture of experts mechanism to the embedding layer to improve the generalization ability and performance of the model;
[0033] Perform a linear transformation on the first feature In1t and then input it into the first bidirectional Transformer encoder for processing to obtain the first high-level feature Out1;
[0034] After performing a linear transformation on the second feature In2t, it is combined with the first token of the first high-level feature Out1 Stack them to obtain stacked features In2ts; then input the stacked features In2ts into the second bidirectional Transformer encoder for processing to obtain second-level advanced features Out2.
[0035] The detection module specifically includes the following content:
[0036] Add the first tokens of the extracted features Out0 and the first-level advanced features Out1 and the first token of the second-level advanced features Out2 After addition, process through the softmax layer to obtain the output distribution Out; the output distribution Out corresponds to the probability of the category to which the input DNS domain name belongs.
[0037] The training described in step S4 specifically includes the following steps:
[0038] Adopt the cross-entropy loss function as the loss function in the training process;
[0039] During training, adopt the backpropagation algorithm to update the constructed model parameters according to the gradient of the loss function.
[0040] The present invention also provides a system for implementing the DNS covert tunnel detection method, which includes a domain name acquisition module, a domain name processing module, a model construction module, a model training module, and a domain name detection module; the domain name acquisition module, the domain name processing module, the model construction module, the model training module, and the domain name detection module are connected in series in sequence; the domain name acquisition module is used to acquire the existing DNS domain name data set and upload the data information to the domain name processing module; the domain name processing module is used to preprocess the acquired DNS domain name data set according to the received data information to construct a training data set and upload the data information to the model construction module; the model construction module is used to construct an initial DNS covert tunnel detection model including an entropy value calculation module, a feature extraction module, a word segmentation module, a Transformer encoder module, and a detection module based on the entropy value scheme, a multi-layer perceptron, a word segmentation scheme, and a Transformer encoder according to the received data information and upload the data information to the model training module; among them, the entropy value calculation module is used to calculate the entropy value of the input DNS domain name and upload the entropy value data to the feature extraction module; the feature extraction module is used to extract the feature data of the input DNS domain name according to the entropy value information; the word segmentation module is used to construct an index sequence for the input DNS domain name; the Transformer encoder module is used to fuse the feature data and the index sequence of the input DNS domain name to achieve feature encoding; the detection module is used to fuse the feature encoding information and the feature data and implement the detection of the DNS covert tunnel; the model training module is used to train the constructed initial DNS covert tunnel detection model with the constructed training data set according to the received data information to obtain a DNS covert tunnel detection model and upload the data information to the domain name detection module; the domain name detection module is used to perform the actual detection of the DNS covert tunnel by using the obtained DNS covert tunnel detection model according to the received data information.
[0041] The DNS covert tunnel detection method and system provided by the present invention not only realize the detection of DNS covert tunnels, but also have reliable detection results and high accuracy by acquiring and marking DNS domain name data and constructing a DNS covert tunnel detection model based on the entropy value scheme, a multi-layer perceptron, a word segmentation scheme, and a Transformer encoder. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] Figure 1 It is a schematic flow chart of the method of the present invention.
[0043] Figure 2 It is a schematic diagram of the functional modules of the system of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0044] Such as Figure 1The following is a schematic diagram of the method flow of the method of the present invention: This DNS covert tunnel detection method disclosed by the present invention includes the following steps:
[0045] S1. Obtain the existing DNS domain name dataset.
[0046] S2. Preprocess the DNS domain name dataset obtained in step S1 to construct a training dataset; specifically, it includes the following steps:
[0047] Clean the DNS domain name data in the DNS domain name dataset obtained in step S1.
[0048] Mark the category of the DNS domain name data after data cleaning; the categories include the normal category and the abnormal category (corresponding to the domain name containing a covert tunnel).
[0049] Finally, construct a training dataset.
[0050] S3. Based on the entropy value scheme, multi-layer perceptron, word segmentation scheme, and Transformer encoder, construct a DNS covert tunnel detection initial model including an entropy value calculation module, a feature extraction module, a word segmentation module, a Transformer encoder module, and a detection module.
[0051] The entropy value calculation module is used to calculate the entropy value of the input DNS domain name and upload the entropy value data to the feature extraction module; the feature extraction module is used to extract the feature data of the input DNS domain name according to the entropy value information; the word segmentation module is used to construct an index sequence for the input DNS domain name; the Transformer encoder module is used to fuse the feature data and the index sequence of the input DNS domain name to achieve feature encoding; the detection module is used to fuse the feature encoding information and the feature data and realize the detection of DNS covert tunnels.
[0052] Specifically, when implementing:
[0053] Construct an entropy value calculation module based on the entropy value scheme to calculate the entropy value of the input DNS domain name; specifically, it includes the following content:
[0054] For the input DNS domain name, use the following formula to calculate the corresponding entropy value H: In the formula is the proportion of the i-th character of the input DNS domain name in the input DNS domain name; is the i-th character of the input DNS domain name; n is the total length of the input DNS domain name; in DNS tunnel detection, the entropy value of a normal domain name is relatively stable, while for a domain name used for a covert tunnel, due to the encoded data, the randomness of characters increases, and the entropy value is often relatively high; therefore, by comparing the entropy values, it can be used to assist in judging whether there is a DNS tunnel.
[0055] Use several cascaded multi-layer perceptrons as the feature extraction module to extract the feature data of the input DNS domain name according to the entropy value information; specifically, it includes the following content:
[0056] For the input DNS domain name, obtain the corresponding entropy value H, then count the length L of the domain name and the number C of sub-domains, and form the input vector Ln as ;
[0057] Input the input vector Ln into the feature extraction module composed of several cascaded multi-layer perceptrons to obtain the extracted feature Out0.
[0058] Build a tokenization module based on the tokenizer to build an index sequence for the input DNS domain name; specifically, it includes the following content:
[0059] Use the tokenizer to analyze the input DNS domain name to build the first index sequence In1 and the second index sequence In2; among them, for the DNS domain name, set the full domain name as s2, and the part from the second-level domain name to the end of the domain name as s1. Use the tokenization tool to tokenize s1 to get the first tokenization result tokens1, tokenize s2 to get the second tokenization result tokens2, and then use the tensor() method on tokens1 to build the first index sequence In1, and use the tensor() method on tokens2 to build the second index sequence In2;
[0060] For example, taking the five-level domain name "sub1.sub2.sub3.example.com" as an example, apply the GPT-2 tokenizer to "example.com" and "sub1.sub2.sub3.example.com" respectively, and then use the open-source toolkit PyTorch to use the tensor() method on the tokenization results to build the index sequences In1 and In2.
[0061] Build a Transformer encoder module based on the bidirectional Transformer encoder and the mixture of experts mechanism to fuse the feature data and index sequence of the input DNS domain name to achieve feature encoding; specifically, it includes the following content:
[0062] Map the first index sequence In1 to the feature space through the embedding layer to obtain the first feature In1t; at the same time, map the second index sequence In2 to the feature space through the embedding layer to obtain the second feature In2t; add a mixture-of-experts mechanism to the embedding layer to improve the generalization ability and performance of the model; the mixture-of-experts mechanism directly determines which expert model to use according to the actual domain name length and entropy. If the input length and entropy reach the predefined threshold, the corresponding expert model is activated; through the combination of multiple expert models, the mixture-of-experts mechanism can better adapt to different types of inputs and improve the generalization ability and performance of the model;
[0063] Perform a linear transformation on the first feature In1t and then input it into the first bidirectional Transformer encoder for processing to obtain the first high-level feature Out1;
[0064] After performing a linear transformation on the second feature In2t, stack it with the first token of the first high-level feature Out1 to obtain the stacked feature In2ts; then input the stacked feature In2ts into the second bidirectional Transformer encoder for processing to obtain the second high-level feature Out2;
[0065] Transformer is a deep learning model based on the self-attention mechanism that can effectively capture long-range dependencies in the sequence; the bidirectional Transformer can process the sequence from both the forward and backward directions simultaneously, thus better obtaining context information; the advantages of the bidirectional Transformer encoder are as follows: First, it has powerful feature extraction capabilities. Different from traditional models that rely on manual features, it can automatically and deeply mine rich features in DNS domain names, not only limited to the character level, but also able to understand at the word level and semantic level, thus providing a strong basis for accurately judging whether there is a DNS tunnel. Second, through the self-attention mechanism, the bidirectional Transformer encoder can effectively handle long-range dependencies, which is crucial for dealing with the complex association relationships between characters and subdomains in the DNS query sequence. It can simultaneously focus on all positions in the sequence, accurately capture long-range dependencies, greatly improving the understanding ability of the domain name structure and semantics, and thus enhancing the detection accuracy. Third, by processing the sequence from both the forward and backward directions, the bidirectional Transformer encoder can obtain more comprehensive context information, avoiding misjudgments due to local information. When judging whether a domain name is used for a covert tunnel, this comprehensive context understanding ability is particularly critical.
[0066] A detection module is constructed using a softmax layer, which is used to fuse feature encoding information and feature data and output the probability of the category corresponding to the input DNS domain name. Specifically, it includes the following content:
[0067] Add the first tokens of the extracted feature Out0, the first high-level feature Out1 and the first token of the second high-level feature Out2 After addition, it is processed through a softmax layer to obtain the output distribution Out; the output distribution Out corresponds to the probability of the category to which the input DNS domain name belongs.
[0068] S4. Use the training dataset constructed in step S2 to train the initial DNS covert tunnel detection model constructed in step S3 to obtain a DNS covert tunnel detection model;
[0069] In the specific training process, a cross-entropy loss function is used as the loss function for the training process;
[0070] During training, the backpropagation algorithm is used to update the constructed model parameters according to the gradient of the loss function.
[0071] S5. Use the DNS covert tunnel detection model obtained in step S4 to perform actual detection of DNS covert tunnels.
[0072] The method of the present invention will be further described below in conjunction with an embodiment:
[0073] Two datasets are used to compare the method of the present invention with existing solutions. The two datasets are the GitHub dataset and the China Unicom dataset CUT.
[0074] The GitHub dataset has 10,481 positive samples and 434 negative samples; during the experiment, The dataset is randomly divided into a training set, a validation set, and a test set at a ratio of to ensure that the ratio of positive and negative samples in all subsets remains the same; each model is only trained on the training set, evaluated on the validation set, and the model with the best performance on the evaluation set is used on the test set.
[0075] China Unicom dataset CUT is formed by collecting regular office network traffic data from the core switches of the provincial office networks operated by China Unicom to form the CUT dataset; the positive samples are domain names collected from regular office traffic and the domain names of Alexa
[2020] TOP50000, while the negative samples are collected using tools such as DETQasim
[2018] , dns2tcp Dembour and Collignon
[2017] , dnscat2 Bowes
[2015] , DNSExfiltrator Arno0x0x
[2018] , DNSlivery no0be
[2019] , iodine Ekman
[2014] , and reverse DNS shellahhh
[2015] ; the complete dataset includes 107,131 positive samples and 119,323 negative samples; the data is randomly split into training set, validation set and test set in a certain proportion, which ensures that the proportion of positive and negative samples remains consistent in all subsets; each model is trained only on the training set, evaluated on the validation set, and the model with the best performance on the evaluation set is adopted on the test set.
[0076] On the above two datasets, the method of the present invention is experimented with the existing solutions, and the evaluation metrics adopted include accuracy, recall, precision and F1 value. The specific data are shown in Tables 1 and 2:
[0077] Table 1 Comparison of evaluation metric data for experiments on GitHub dataset
[0078]
[0079] Table 2 Comparison of evaluation metric data for experiments on China Unicom dataset CUT
[0080]
[0081] Among them, the VM model was systematically described by Vladimir Vapnik et al. in the book "The Nature of Statistical Learning Theory" in 1995; the CNN model was a solution proposed by Yann LeCun et al. in the paper "Gradient - Based Learning Applied to Document Recognition" in 1998; the LSTM model was a solution proposed by Sepp Hochreiter and Jürgen Schmidhuber in the paper "Long Short - Term Memory" in 1997; the simple model (directly using features) refers to a relatively simple and direct bidirectional transducer model that directly takes all the token indices of the domain name as input without using a complex hierarchical structure; the hierarchical model is the complete model proposed by the method of the present invention.
[0082] As can be seen from Table 1 and Table 2, the solution proposed by the method of the present invention has achieved excellent results on both datasets. This demonstrates the effectiveness and accuracy of the method of the present invention.
[0083] Then, different tokenizers and algorithm models are combined and experiments are carried out on the China Unicom dataset. The experimental result indicators are shown in Table 3:
[0084] Table 3 Schematic table for comparing experimental evaluation index data of different tokenizers
[0085]
[0086] As can be seen from Table 3, the comprehensive performance of the solution of the present invention and the GPT - 2 tokenizer used is the best, and excellent results have been achieved in all indicators. This also demonstrates the effectiveness and accuracy of the method of the present invention.
[0087] Such as Figure 2The following is a schematic diagram of the functional modules of the system of the present invention: The system for implementing the DNS covert tunnel detection method disclosed in the present invention includes a domain name acquisition module, a domain name processing module, a model construction module, a model training module, and a domain name detection module; the domain name acquisition module, the domain name processing module, the model construction module, the model training module, and the domain name detection module are connected in series in sequence; the domain name acquisition module is used to acquire the existing DNS domain name data set and upload the data information to the domain name processing module; the domain name processing module is used to preprocess the acquired DNS domain name data set according to the received data information to construct a training data set and upload the data information to the model construction module; the model construction module is used to construct an initial DNS covert tunnel detection model including an entropy value calculation module, a feature extraction module, a word segmentation module, a Transformer encoder module, and a detection module based on the entropy value scheme, a multi-layer perceptron, a word segmentation scheme, and a Transformer encoder according to the received data information and upload the data information to the model training module; among them, the entropy value calculation module is used to calculate the entropy value of the input DNS domain name and upload the entropy value data to the feature extraction module; the feature extraction module is used to extract the feature data of the input DNS domain name according to the entropy value information; the word segmentation module is used to construct an index sequence for the input DNS domain name; the Transformer encoder module is used to fuse the feature data and the index sequence of the input DNS domain name to implement feature encoding; the detection module is used to fuse the feature encoding information and the feature data and implement the detection of the DNS covert tunnel; the model training module is used to train the constructed initial DNS covert tunnel detection model using the constructed training data set according to the received data information to obtain a DNS covert tunnel detection model and upload the data information to the domain name detection module; the domain name detection module is used to perform the actual detection of the DNS covert tunnel using the obtained DNS covert tunnel detection model according to the received data information.
Claims
1. A DNS hidden tunnel detection method, characterized in that The steps include: S1. Obtain the existing DNS domain name dataset; S2. Preprocessing the DNS domain name dataset obtained in step S1 to construct a training dataset; S3. Based on the entropy scheme, multi-layer perceptron, word segmentation scheme and Transformer encoder, an initial model for DNS covert tunnel detection is constructed, which includes an entropy calculation module, a feature extraction module, a word segmentation module, a Transformer encoder module and a detection module; The entropy value calculation module is used to calculate the entropy value of the input DNS domain name and upload the entropy value data to the feature extraction module; The feature extraction module is used to extract the feature data of the input DNS domain name according to the entropy value information; the word segmentation module is used to construct an index sequence for the input DNS domain name; the Transformer encoder module is used to fuse the feature data and index sequence of the input DNS domain name to achieve feature encoding; the detection module is used to fuse the feature encoding information and feature data and realize the detection of DNS covert tunnels; The word segmentation module specifically includes the following contents: A tokenizer is used to analyze the input DNS domain name to construct a first index sequence In1 and a second index sequence In2; wherein, for the DNS domain name, the complete domain name is set as s2, and the part from the second-level domain name to the end of the domain name is s1. The tokenizer is used to tokenize s1 to obtain the first tokenization result tokens1, and s2 is tokenized to obtain the second tokenization result tokens2. Then, the tensor() method is used to construct tokens1 to obtain the first index sequence In1, and the tensor() method is used to construct tokens2 to obtain the second index sequence In2. Transformer encoder module, specifically including the following: The first index sequence In1 is mapped to the feature space through the embedding layer to obtain the first feature In1t; at the same time, the second index sequence In2 is mapped to the feature space through the embedding layer to obtain the second feature In2t; an expert mixture mechanism is added to the embedding layer to improve the generalization ability and performance of the model; The first feature In1t is linearly transformed and then input into the first bidirectional Transformer encoder for processing to obtain the first high-level feature Out1; After linear transformation of the second feature In2t, the first tag of the first high-level feature Out1 The stacked features In2ts are obtained by stacking. The stacked features In2ts are then input into the second bidirectional Transformer encoder for processing to obtain the second high-level features Out2. S4 using the training data set constructed in step S2, the DNS covert tunnel detection initial model constructed in step S3 is trained to obtain a DNS covert tunnel detection model; S5. Using the DNS covert tunnel detection model obtained in step S4, perform actual DNS covert tunnel detection.
2. The DNS hidden tunnel detection method according to claim 1 is characterized in that The step S2 specifically includes the following steps: Performing data cleaning on the DNS domain name data in the DNS domain name data set obtained in step S1; Marking the DNS domain name data after data cleaning into categories; the categories include normal categories and abnormal categories; Finally, the training dataset is constructed.
3. The DNS hidden tunnel detection method according to claim 1 or 2, characterized in that The step S3 comprises the following steps: An entropy value calculation module is constructed based on the entropy value scheme to calculate the entropy value of the input DNS domain name; A number of multi-layer perceptrons connected in series are used as feature extraction modules to extract feature data of input DNS domain names according to entropy information; A word segmentation module is built based on the word segmenter to construct an index sequence for the input DNS domain name; A Transformer encoder module is constructed based on a bidirectional Transformer encoder and an expert mixture mechanism to fuse the feature data and index sequence of the input DNS domain name to achieve feature encoding; The softmax layer is used to build the detection module, which is used to fuse the feature encoding information and feature data, and output the probability of the category corresponding to the input DNS domain name.
4. The DNS hidden tunnel detection method according to claim 3 is characterized in that The entropy value calculation module specifically includes the following contents: For the input DNS domain name, the corresponding entropy value H is calculated using the following formula: In the formula is the proportion of the iith character of the input DNS domain name that appears in the input DNS domain name; is the iith character of the entered DNS domain name; nn is the total length of the entered DNS domain name.
5. The DNS hidden tunnel detection method according to claim 4 is characterized in that The feature extraction module specifically includes the following contents: For the input DNS domain name, obtain the corresponding entropy value H, and then count the length L of the domain name and the number of subdomains C to form the input vector Ln: ; The input vector Ln is input into a feature extraction module composed of several multi-layer perceptrons connected in series to obtain the extracted feature Out0.
6. The DNS hidden tunnel detection method according to claim 5 is characterized in that The detection module specifically includes the following contents: The first tag of feature Out0 and first high-level feature Out1 will be extracted and the first token of the second high-level feature Out2 After addition, the output distribution Out is obtained through the softmax layer processing; the output distribution Out corresponds to the probability of the category to which the input DNS domain name belongs.
7. The DNS hidden tunnel detection method according to claim 1 or 2, characterized in that The training described in step S4 specifically includes the following steps: The cross entropy loss function is used as the loss function of the training process; During training, the back-propagation algorithm is used to update the constructed model parameters according to the gradient of the loss function.
8. A system for implementing the DNS covert tunnel detection method according to any one of claims 1 to 7, characterized in that It includes a domain name acquisition module, a domain name processing module, a model building module, a model training module and a domain name detection module; the domain name acquisition module, the domain name processing module, the model building module, the model training module and the domain name detection module are connected in series in sequence; the domain name acquisition module is used to obtain the existing DNS domain name data set and upload the data information to the domain name processing module; The domain name processing module is used to pre-process the acquired DNS domain name data set according to the received data information to construct a training data set, and upload the data information to the model construction module; The model building module is used to construct a DNS hidden tunnel detection initial model including an entropy calculation module, a feature extraction module, a word segmentation module, a Transformer encoder module and a detection module based on the received data information, based on the entropy scheme, the multi-layer perceptron, the word segmentation scheme and the Transformer encoder, and upload the data information to the model training module; wherein the entropy calculation module is used for the entropy value of the input DNS domain name, and the entropy value data is uploaded to the feature extraction module; the feature extraction module is used to extract the feature data of the input DNS domain name according to the entropy information; the word segmentation module is used to construct an index sequence for the input DNS domain name; the Transformer encoder module is used to fuse the feature data and index sequence of the input DNS domain name to realize feature encoding; the detection module is used to fuse the feature encoding information and the feature data, and realize the detection of the DNS hidden tunnel; the model training module is used to train the constructed DNS hidden tunnel detection initial model according to the received data information using the constructed training data set to obtain the DNS hidden tunnel detection model, and upload the data information to the domain name detection module; the domain name detection module is used to perform actual DNS hidden tunnel detection according to the received data information using the obtained DNS hidden tunnel detection model.
Citation Information
Patent Citations
Concealed channel identification method and device, computer equipment and storage medium
CN116232673A
DNS covert channel detection method and system
CN117176422A