DNS tunnel identification method and device, and machine readable medium

By building a fully connected neural network model and DNS sample vector, the problems of low recognition accuracy and high computational volume in the existing DNS tunnel recognition methods are solved, and efficient and real-time DNS tunnel detection is achieved, which is suitable for network equipment.

CN120238348APending Publication Date: 2025-07-01BEIJING JIUDING SHUAN TECHNOLOGY CO LTD
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN202510377477.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-27
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

The existing DNS tunnel recognition methods have problems such as low recognition accuracy, large calculation amount and poor real-time performance, especially in network equipment, it is difficult to effectively detect DNS tunnel activities.

Method used

DNS tunnel recognition method based on a fully connected neural network model is constructed. By constructing DNS sample vectors and simplifying neural network structures, DNS tunnel recognition is performed by combining a fully connected neural network model, including the input layer, the first hidden layer, the second hidden layer and the output layer, the SIGMOID activation function is used, and the mean square error calculation method is used.

Benefits of technology

It improves the accuracy and efficiency of DNS tunnel recognition, reduces the calculation amount and identification time, and is suitable for real-time detection of DNS tunnels in network devices, meets communication delay requirements, and is suitable for equipment with strict real-time requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238348A_ABST
    Figure CN120238348A_ABST
Patent Text Reader

Abstract

The invention provides a domain name system (DNS) tunnel identification method, equipment and a machine readable medium. The method may comprise: obtaining DNS traffic within a sampling unit time from an input signal; constructing a DNS sample vector based on the DNS traffic; providing the DNS sample vector as an input to the trained machine learning model; obtaining model output of the trained machine learning model; and identifying whether a DNS tunnel exists in the DNS traffic based on the model output.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of network security technology, and more particularly, to a method, device, and machine-readable medium for identifying a Domain Name System (DNS) tunnel based on a neural network. Background Art

[0002] The DNS domain name resolution system is a basic service in the Internet, which is used to map IP addresses and domain names to each other. The DNS domain name resolution system is crucial for the normal operation of the Internet because users are usually more likely to remember domain names rather than IP addresses, and the DNS domain name resolution system can facilitate users to access the Internet through domain names.

[0003] A DNS tunnel is a technology that uses the Domain Name System (DNS) protocol to transmit data. It can bypass conventional network monitoring means, encode any data into the form of DNS queries, and thus achieve the purpose of hiding communication in DNS traffic. DNS tunnel technology is usually used by malicious actors for covert communication, data leakage, or other offensive purposes because normal firewall configurations often do not block DNS traffic. Therefore, detecting DNS tunnel activities has become an important issue in the field of network security. Summary of the Invention

[0004] The present disclosure provides a method, device, and machine-readable medium for identifying a DNS tunnel.

[0005] According to one aspect of the present disclosure, a method for identifying a Domain Name System (DNS) tunnel is provided. The method may include: obtaining DNS traffic within a sampling unit time from an input signal; constructing a DNS sample vector based on the DNS traffic; providing the DNS sample vector as an input to a trained machine learning model; obtaining a model output of the trained machine learning model; and identifying whether there is a DNS tunnel in the DNS traffic based on the model output.

[0006] According to the method of the present disclosure, wherein the parameters of the DNS sample vector include: the minimum length of the response name, the maximum length of the response name, the average length of the response name, the standard variance of the length of the response name, the minimum value of the number of labels in the response name, the maximum value of the number of labels in the response name, the average value of the number of labels in the response name, and the standard variance of the number of labels in the response name.

[0007] According to the method of the present disclosure, wherein the trained machine learning model is a neural network model.

[0008] According to the method of the present disclosure, wherein the neural network model includes an input layer, a first hidden layer, a second hidden layer, and an output layer.

[0009] The method according to the present disclosure, wherein both the input layer and the first hidden layer include neurons with the number of parameters of the DNS sample vector; the second hidden layer includes neurons with half the number of parameters of the DNS sample vector; and the output layer includes one neuron.

[0010] The method according to the present disclosure, wherein a fully connected connection method is adopted between the input layer, the first hidden layer, the second hidden layer and the output layer.

[0011] The method according to the present disclosure, wherein the output layer uses SIGMOID as the activation function, and its range is [-1, 1].

[0012] The method according to the present disclosure, wherein the error calculation method of the trained machine learning model is the mean square error (MSE).

[0013] According to another aspect of the present disclosure, there is provided a device for identifying a Domain Name System (DNS) tunnel. The device may include: a memory for storing instructions; and at least one processor coupled to the memory and configured to execute the instructions to perform the method for identifying a Domain Name System (DNS) tunnel as described herein.

[0014] According to another aspect of the present disclosure, there is provided a machine-readable medium including instructions that, when executed by at least one processor, cause the at least one processor to perform the method for identifying a Domain Name System (DNS) tunnel as described herein. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] From the following description in conjunction with the drawings, the above and other aspects, features and advantages of certain embodiments of the present disclosure will become more apparent. In the drawings:

[0016] Figure 1 A flowchart of a method for identifying a DNS tunnel according to an exemplary embodiment of the present disclosure is shown.

[0017] Figure 2 An exemplary structure and data flow diagram of a DNS tunnel identification device according to an exemplary embodiment of the present disclosure are shown.

[0018] Figure 3 A flowchart of a method for training a machine learning model according to an exemplary embodiment of the present disclosure is shown.

[0019] Figure 4 A block diagram of an electronic device according to an exemplary embodiment of the present disclosure is shown. DETAILED DESCRIPTION

[0020] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present disclosure. It should also be understood that the drawings and embodiments of the present disclosure are for illustrative purposes only and are not used to limit the protection scope of the present disclosure.

[0021] It should be understood that the various steps recorded in the method embodiments of the present disclosure can be executed in different orders and / or executed in parallel. In addition, the method embodiments may include other steps and / or omit certain steps. In the present disclosure, descriptions of details well known in the art are omitted to avoid unnecessarily obscuring the scope of the present disclosure.

[0022] As used herein, the term "including" and its variants are open-ended, that is, "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". The relevant definitions of other terms will be given in the following description.

[0023] It should be understood that the concepts such as "first", "second", etc. mentioned in the present disclosure are only used to distinguish different devices, equipment, modules, units, models, data, etc., and are not used to limit the order of functions performed by these devices, equipment, modules, units, models, data, the order of generation, or the interdependent relationship.

[0024] It should be noted that the modification of "one" and "multiple" mentioned in the present disclosure is illustrative rather than restrictive. Those skilled in the art should understand that unless otherwise clearly specified in the context, it should be understood as "one or more".

[0025] Generally, there are several main identification methods for DNS tunnels as follows:

[0026] Method 1: Statistical-based identification method.

[0027] In the statistical-based identification method, DNS traffic is obtained from the input signal, and statistical characteristics such as the number, frequency, and size of DNS queries are observed to detect whether there is DNS tunnel activity (which can be abbreviated as DNS tunnel hereinafter) in the DNS traffic. Generally speaking, uncommon high-frequency DNS interactions or DNS queries with unconventional quantities may indicate DNS tunnel activity.

[0028] Method 2: Behavior model-based identification method.

[0029] In the behavior model-based recognition method, first, a machine learning algorithm is used to train a behavior model. The trained behavior model is used to identify and detect normal DNS query patterns and abnormal DNS query patterns, so as to identify DNS tunnels.

[0030] In the behavior model-based recognition method, common behavior models include Support Vector Machine (SVM) or convolutional neural network (CNN), etc.

[0031] However, the foregoing DNS tunnel recognition methods all have defects.

[0032] For example, in the statistic-based recognition method, the recognition result is overly dependent on the sampled situation. For unknown scenarios, due to the small number of samples collected and the lack of sample support, the statistic-based recognition method usually has low detection quality and low recognition accuracy for DNS tunnels.

[0033] In addition, in the behavior model-based recognition method, different defects exist according to different behavior models adopted. For example, the SVM model does not extract sufficient features of DNS traffic, resulting in inaccurate recognition of DNS tunnels and inability to further distinguish similar situations. Another example is that the convolutional neural network model has too many neurons, and operations such as convolution are computationally complex, resulting in a large amount of computation and a long detection time during the detection process of DNS tunnels, which is not suitable for use in devices with strict real-time requirements such as network devices.

[0034] In view of the above defects, according to the embodiments of the present disclosure, a DNS tunnel recognition method, device, and machine-readable medium are provided.

[0035] In the present disclosure, for the recognition of DNS tunnels, a sample vector composed of predetermined parameters is constructed. During the construction process of the sample vector, key features related to the recognition of DNS tunnels in DNS traffic can be extracted in a targeted manner, and these features are represented in the form of a sample vector for the pre-training of a machine learning model and the post-processing of the trained machine learning model, thereby helping to train the machine learning model to perform high-quality recognition of DNS tunnels and achieving high-quality recognition of DNS tunnels during actual application. Compared with the statistic-based recognition method, even for unknown scenarios, the sample vector construction method in the present disclosure is beneficial to the effective training of the machine learning model, enabling the DNS recognition method based on this machine learning model to solve the problem of lack of sample support and effectively improving the DNS tunnel detection quality.

[0036] In the present disclosure, for the identification of DNS tunnels, a machine learning model is also constructed, for example, a neural network model. By restricting the number and connection mode of neurons of the neural network model and using a simplified calculation method, the identification accuracy and identification time of DNS tunnels are taken into account, and while effectively identifying DNS tunnels, the requirements of communication delay of network devices are met. In addition, the structure of the neural network model of the present disclosure determines that the neural network model extracts features more fully than SVM, thereby improving the identification accuracy of DNS tunnels compared with SVM. Based on this, even in the case of similar DNS traffic, the neural network model of the present disclosure can make further distinctions. In addition, since the neural network model of the present disclosure has a simpler structure compared with CNN, the computational amount in the identification and training processes is significantly reduced. Therefore, the time in the identification and training processes can be significantly reduced, and while not compromising the identification accuracy, the identification and training efficiency are improved, which is suitable for use in devices with strict real-time requirements such as network devices. In addition, the DNS tunnel identification method of the present disclosure uses a streamlined sample vector and a simplified neural network model. Therefore, relevant network transmission resources, processor resources, computational resources, and memory resources are greatly saved.

[0037] Figure 1 FIG. shows a flowchart of a DNS tunnel identification method 100 according to an exemplary embodiment of the present disclosure.

[0038] According to an embodiment of the present disclosure, the method 100 may be executed in a device for DNS tunnel identification. In an embodiment, the device may be a network device. In an embodiment, the device may be the DNS tunnel identification device 200 described below with reference to Figure 2 the DNS tunnel identification device 200.

[0039] Method 100 starts at step 101. At step 101, DNS traffic is obtained. In an embodiment, the device may obtain DNS traffic from the outside. In an embodiment, obtaining DNS traffic may include the device obtaining DNS traffic from an input signal within a sampling unit time. In an embodiment, a sampling unit of the device may be used to obtain DNS traffic from the input signal. In an embodiment, the sampling unit time may be in units of milliseconds, seconds, minutes, hours, etc. The length of the sampling unit time may be reasonably determined according to the actual application scenario and data collection requirements. In one example, for a DNS tunnel identification scenario, the sampling unit time may be 30 seconds, so as to use 30 seconds as the granularity of DNS tunnel identification. It should be noted that the sampling unit time of 30 seconds is only exemplary and not restrictive, and other sampling unit times may also be used without departing from the scope of the present disclosure. Generally speaking, a larger sampling unit time may correspond to a coarser DNS tunnel identification granularity, which is beneficial to identifying whether there is a DNS tunnel within a longer time period and is beneficial to roughly locating the position of the DNS tunnel. In addition, a larger sampling unit time is also beneficial to ensuring that there are a sufficient number of DNS queries within the sampling unit time to obtain representative data. A smaller sampling unit time may correspond to a finer DNS tunnel identification granularity, which is beneficial to accurately locating the specific position of the DNS tunnel. Although it is described in the present disclosure that DNS traffic may be obtained by a sampling unit of the device, the present disclosure is not limited thereto. For example, at least one processor and / or transceiver of the device may obtain DNS traffic from the input signal.

[0040] In step 103, a DNS sample vector is constructed. Specifically, the device can construct a DNS sample vector (hereinafter simply referred to as a sample vector) based on the DNS traffic obtained in step 101. In an embodiment, the sample vector can be constructed by a sample vector construction unit of the device. In an embodiment, for example, the sample vector construction unit can construct a sample vector by calculating the length of the response name included in the DNS traffic within a sampling unit time (e.g., 30 seconds) and the number of labels in the response name. As an example, the parameters constituting the DNS sample vector can include the minimum length of the response name, the maximum length of the response name, the average length of the response name, the standard variance of the length of the response name, the minimum value of the number of labels in the response name, the maximum value of the number of labels in the response name, the average value of the number of labels in the response name, and the standard variance of the number of labels in the response name, arranged in a predetermined order. It should be understood that the above parameters are only exemplary and not restrictive, and other DNS query-related parameters are also within the scope of the present disclosure. The above parameters of the DNS sample vector are reasonably selected to include key features related to the identification of DNS tunnels in the DNS traffic, so that the constructed sample vector has sufficient representativeness to effectively identify DNS tunnels without being excessive, thus avoiding excessive computational complexity in the DNS tunnel identification process. For example, the requested domain name or the query domain name may be greatly affected by user query habits or other factors. Therefore, it may not be possible to accurately identify DNS tunnels based on the length of the requested domain name or the query domain name or the number of labels it includes. However, the response name is less affected by other influencing factors. Therefore, the response name can be used as a basis for identifying DNS tunnels. Although it is described in the present disclosure that the sample vector can be constructed by the sample vector construction unit of the device, the present disclosure is not limited thereto. For example, at least one processor of the device can be configured to construct a sample vector based on the obtained DNS traffic.

[0041] In an embodiment according to the present disclosure, constructing a sample vector can include arranging the above parameters (i.e., the minimum length of the response name, the maximum length of the response name, the average length of the response name, the standard variance of the length of the response name, the minimum value of the number of labels in the response name, the maximum value of the number of labels in the response name, the average value of the number of labels in the response name, and the standard variance of the number of labels in the response name) in a predetermined order in sequence to form a sample vector containing eight elements. For example, the sample vector can be represented as [the minimum length of the response name, the maximum length of the response name, the average length of the response name, the standard variance of the length of the response name, the minimum value of the number of labels in the response name, the maximum value of the number of labels in the response name, the average value of the number of labels in the response name, the standard variance of the number of labels in the response name], and this sample vector can be used in subsequent DNS tunnel identification and / or machine learning model training processes.

[0042] According to an embodiment of the present disclosure, in step 105, the DNS sample vector constructed in step 103 can be provided to a trained machine learning model as the input of the model. In the embodiment, the trained machine learning model can be a neural network model. In the embodiment, the neural network model can include an input layer, a first hidden layer, a second hidden layer, and an output layer.

[0043] In the embodiment, the input layer, the first hidden layer, the second hidden layer, and the output layer can be connected in a fully connected manner. This fully connected neural network model has the following advantages. During the training and inference processes, the fully connected neural network can parallelize a large number of computational tasks and perform operations such as activation calculation and weight update of multiple neurons simultaneously. This parallel computing ability can not only shorten the training time of the model and optimize and improve the model faster, but also improve the real-time response ability of the model in practical applications, meeting scenarios with high real-time requirements, such as real-time monitoring of DNS tunnels.

[0044] In the embodiment, the DNS sample vector constructed in step 103 can be input into the input layer of the neural network model. Both the input layer and the first hidden layer can include neurons with the number of parameters of the DNS sample vector. Such a design avoids premature loss of information in the initial stage, enabling the neural network model to fully learn the complex representation of the input sample vector, especially suitable for tasks that require retaining details, such as DNS tunnel identification tasks. As mentioned above, a DNS sample vector including eight parameters is constructed. In this case, both the input layer and the first hidden layer can include nine neurons. In the embodiment, the input layer of the neural network includes neurons with the number of parameters of the DNS sample vector, such that each neuron in the input layer receives one parameter of the input sample vector respectively, ensuring that the neural network model can completely receive all parameters of the sample vector arranged in a predetermined order.

[0045] In the embodiment, the second hidden layer can include neurons with half the number of parameters of the DNS sample vector. Halving the number of neurons in the second hidden layer achieves step-by-step dimensionality reduction. This design screens key features by compressing redundant information, enhancing the model's abstraction ability. At the same time, compared with the full-size hidden layer, the number of parameters is reduced (for example, the number of parameters is reduced by 50%), thereby reducing the risk of overfitting and improving the calculation efficiency. The total number of parameters of the neural network model is significantly less than that of the network model with all layers being full-size, making the model training faster and having lower requirements for computing resources. Continuing with the previous example, the number of neurons in the second hidden layer can be determined by dividing the number of parameters of the DNS sample vector by two and rounding if necessary. Continuing with the previous example, the second hidden layer can include four neurons.

[0046] In an embodiment, the output layer may include one neuron. In an embodiment, the output layer may adopt SIGMOID as the activation function, and its range is [-1, 1]. The SIGMOID activation function can perform a non-linear transformation on the input, increasing the expression ability of the neural network, enabling the neural network to learn more complex data patterns. In an embodiment, the model output of the entire neural network model is output at the neuron of the output layer. The single-neuron design of the output layer is naturally suitable for binary classification tasks such as DNS tunnel identification (in combination with the aforementioned SIGMOID activation function), with a simple structure and clear output, avoiding redundant calculations.

[0047] In an embodiment, in the method for identifying a DNS tunnel by processing a DNS sample vector through a neural network model, by considering the constructed DNS sample vector, the number and connection method of neurons in each layer of the neural network model are restricted, such that the amount of computation involved in the processing is significantly less than that of a convolutional neural network. While maintaining the recognition accuracy of the DNS tunnel, the recognition speed is improved and the processing time is shortened. Therefore, this method can effectively identify the DNS tunnel while meeting the requirements of the communication delay of network devices, and is suitable for use in devices with strict real-time requirements such as network devices. At the same time, based on the differences in structure and principle between the fully connected neural network model and the SVM model, the fully connected neural network model of the present disclosure is superior to the SVM model in feature extraction, has a higher recognition accuracy for DNS tunnels, and can further distinguish similar situations.

[0048] In step 107, the model output of the trained machine learning model is obtained. In an embodiment, in the embodiment where the trained machine learning model is the aforementioned neural network model, the model output is output from the output layer of the neural network model. The model output may be a numerical value between -1 and 1.

[0049] In step 109, based on the model output, it is identified whether there is a DNS tunnel in the DNS traffic. In an embodiment, the device may identify whether there is a DNS tunnel in the DNS traffic based on the model output. In an embodiment, the DNS tunnel identification unit of the device may identify whether there is a DNS tunnel in the DNS traffic based on the model output. By way of example and not limitation, the DNS tunnel identification unit may receive the model output from a trained machine learning model and identify whether there is a DNS tunnel in the DNS traffic based on the following. For example, a model output value of 1 may indicate that there is a DNS tunnel in the DNS traffic. For example, a model output value of -1 may indicate that there is no DNS tunnel in the DNS traffic. Therefore, the closer the model output is to 1, the greater the likelihood that the corresponding DNS traffic includes a DNS tunnel, and the closer the model output is to -1, the smaller the likelihood that the corresponding DNS traffic includes a DNS tunnel. A model output close to 0 indicates that it is not possible to determine whether the DNS traffic includes a DNS tunnel. Optionally, in an embodiment, the identification result of the DNS tunnel identification unit may be visually displayed to the user of the device. Optionally, in an embodiment, when the DNS tunnel identification result indicates the existence of DNS tunnel activity, an alert in the form of light, sound, and / or vibration may be issued to the user of the device. Those skilled in the art should understand that although it is described in the present disclosure that the DNS tunnel identification unit of the device may identify whether there is a DNS tunnel in the DNS traffic, the present disclosure is not limited thereto. For example, at least one processor of the device may be configured to identify whether there is a DNS tunnel in the DNS traffic based on the model output. Optionally, the model output of the trained machine learning model may be displayed to directly indicate whether there is a DNS tunnel in the DNS traffic. That is, the DNS tunnel identification unit may be omitted according to requirements.

[0050] Figure 2 FIG. shows an example structure and an example data flow diagram of a DNS tunnel identification device 200 according to an example embodiment of the present disclosure. The DNS tunnel identification device 200 may be configured to use Figure 1 the method shown to identify a DNS tunnel.

[0051] In an embodiment, as Figure 2 shown, the DNS tunnel identification device 200 may include a sampling unit 210, a sample vector construction unit 220, a trained machine learning model 230, and a DNS tunnel identification unit 240.

[0052] In an embodiment, the sampling unit 210 may be configured to obtain DNS traffic. For example, the sampling unit 210 may obtain DNS traffic from an input signal received from outside the DNS tunnel identification device. In an embodiment, the sampling unit 210 may provide the DNS traffic obtained from the input signal within a sampling unit time to the sample vector construction unit 220. In an embodiment, the sampling unit time may be 30 seconds.

[0053] In an embodiment, the sample vector construction unit 220 may receive DNS traffic from the sampling unit 210 and construct a DNS sample vector based on the DNS traffic. In an embodiment, the sample vector construction unit 220 may construct a sample vector by calculating corresponding parameters of DNS request packets and DNS response packets included in the DNS traffic within a sampling unit time (e.g., 30 seconds), as the output of the sample vector construction unit 220. As an example, the parameters constituting the DNS sample vector may include the minimum length of the response name, the maximum length of the response name, the average length of the response name, the standard variance of the length of the response name, the minimum value of the number of labels in the response name, the maximum value of the number of labels in the response name, the average value of the number of labels in the response name, and the standard variance of the number of labels in the response name. The above parameters arranged in a predetermined order may form a DNS sample vector.

[0054] After constructing the DNS sample vector, the sample vector construction unit 220 may provide the constructed DNS sample vector to the trained machine learning model 230.

[0055] In an embodiment, the trained machine learning model 230 may be a neural network model as described in the reference Figure 1 The trained machine learning model 230 may process the DNS sample vector provided by the sample vector construction unit 220 and output a model output. Subsequently, the trained machine learning model 230 may provide the model output to the DNS tunnel identification unit 240.

[0056] In an embodiment, the DNS tunnel identification unit 240 may identify whether there is a DNS tunnel in the DNS traffic obtained from the input signal based on the model output received from the trained machine learning model 230 and output a DNS tunnel identification result. The DNS tunnel identification unit 240 may be based on the reference Figure 1Identify whether there is a DNS tunnel in DNS traffic in the described manner. For example, the model output value of 1 can indicate the existence of a DNS tunnel in DNS traffic. For example, the model output value of -1 can indicate the non-existence of a DNS tunnel in DNS traffic. Therefore, the closer the model output is to 1, the greater the possibility that the corresponding DNS traffic includes a DNS tunnel, and the closer the model output is to -1, the smaller the possibility that the corresponding DNS traffic includes a DNS tunnel. When the model output is close to 0, it indicates that it is impossible to determine whether the DNS traffic includes a DNS tunnel. Optionally, in an embodiment, the identification result of the DNS tunnel identification unit 240 can be visually displayed to the user of the DNS tunnel identification device 200. Optionally, in an embodiment, when the DNS tunnel identification result indicates the existence of DNS tunnel activity, an alarm in the form of light, sound, and / or vibration can be issued to the user of the DNS tunnel identification device 200.

[0057] Figure 3 The flowchart of a method 300 for training a machine learning model according to an exemplary embodiment of the present disclosure is shown.

[0058] In an embodiment, the machine learning model to be trained can be the four-layer fully connected neural network model as described above. That is, the neural network model can include an input layer, a first hidden layer, a second hidden layer, and an output layer connected in a fully connected manner. The activation function of the output layer can be SIGMOID, and its range can be [-1, 1].

[0059] In method 300, in step 310, a plurality of training sample vectors are constructed. In an embodiment, each of the training sample vectors is similar to the DNS sample vectors constructed as previously referenced Figure 1 as described. That is, each of the training sample vectors has eight parameters arranged in a predetermined order as previously referenced Figure 1 as described. In addition, each of the training sample vectors also has a label indicating whether the DNS traffic corresponding to the training sample vector includes a DNS tunnel, that is, the ground truth. In an embodiment, optionally, the plurality of training sample vectors include a sufficient number of positive training sample vectors and a sufficient number of negative training sample vectors. In an embodiment, to improve efficiency, the training sample vectors can be manually collected and made. Without limiting the collection time, relatively representative data can be manually extracted from the traffic to make the training sample vectors.

[0060] In step 320, the constructed plurality of training sample vectors are input into the machine learning model to be trained. When the machine learning model to be trained is a four-layer fully connected neural network model, the constructed plurality of training sample vectors are input into the input layer of the neural network model.

[0061] In step 330, calculate the error between the model output of the trained machine learning model and the true value.

[0062] In an embodiment, multiple training sample vectors are processed using the trained machine learning model to obtain a model output. When the trained machine learning model is the four-layer fully connected neural network model described in the reference Figure 1 description, the parameters of each training sample vector are processed through a neural network model similar to that described in the reference Figure 1 description to obtain a model output. In an embodiment, an appropriate method is used to calculate the error of the model output. In an embodiment, the error calculation method for the trained machine learning model is the mean square error (MSE). That is, calculate the mean square error between the model output of the trained machine learning model and the true value as the error.

[0063] In step 340, adjust the weights of the trained machine learning model based on the error. In an embodiment, for example, gradually adjust the weights of the trained machine learning model based on the error calculated in step 330 to minimize the error. Determine the weights of the machine learning model when the error is minimized as the final weights of the model.

[0064] The model trained using the above method 300 can be used to identify DNS tunnels in actual DNS traffic.

[0065] A method for identifying DNS tunnel behavior based on a machine learning model (e.g., a four-layer fully connected neural network model) is provided in the present disclosure. Compared with the identification method based on a standard convolutional neural network model, the method of the present disclosure has advantages such as small computational amount and short detection time while ensuring the identification accuracy. In addition, the method of the present disclosure has a higher identification accuracy than other traditional detection methods, such as the statistical-based identification method and the SVM-based identification method.

[0066] The neural network model constructed in the present disclosure has high identification accuracy, a wide range of applicable scenarios, small computational amount, and fast detection speed. At least based on the foregoing advantages, the method of the present disclosure will not affect the network communication quality when used in network devices, and is particularly suitable for use in devices with strict real-time requirements.

[0067] Figure 4 A block diagram of an electronic device according to an exemplary embodiment of the present disclosure is shown. In an embodiment, the electronic device may be the device described in the reference Figure 1 or the DNS tunnel identification device 200 described in the reference Figure 2 .

[0068] Reference Figure 4, the electronic device 400 may include a memory 410, at least one processor 420, and a transceiver 430. Under the control of the at least one processor 420, the electronic device 400 (including the memory 410 and the transceiver 430) may be configured to perform the operations of the methods or devices described herein. Although the memory 410, the at least one processor 420, and the transceiver 430 are shown as separate entities, they may be implemented as a single entity, such as a single chip. The memory 410, the at least one processor 420, and the transceiver 430 may be electrically connected or coupled to each other. Optionally, the transceiver 430 of the electronic device 400 may be omitted. The transceiver 430 may be configured to send signals to other network entities and / or receive signals from other network entities. In the case where the transceiver 430 is omitted, the at least one processor 420 may be configured to execute instructions stored in the memory 410 to control the overall operation of the electronic device 400, thereby performing the operations of the methods or devices described herein.

[0069] The whole or parts of the electronic devices described in this disclosure may be implemented by various suitable hardware means, including but not limited to field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), systems on a chip (SoCs), discrete gate or transistor logic, discrete hardware components, or any combination thereof. The apparatuses, devices, methods, and systems involved in this disclosure are not limited to any predetermined hardware architecture or configuration. The components in the disclosed apparatuses, devices, and systems may be separate or integrated, and may be combined in different ways and / or replaced or supplemented by other components. It should be understood that the teachings of this disclosure may be implemented in various forms of hardware, software, firmware, dedicated processors, or combinations thereof.

[0070] The block diagrams of the apparatuses, devices, units, etc. involved in this disclosure are merely exemplary and are not intended to require or imply that they must be connected, arranged, and configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these apparatuses, devices, and units may be connected, arranged, and configured in any way as long as the desired purpose can be achieved.

[0071] In the above description, this disclosure has been described based on embodiments. These embodiments are merely illustrative, and those skilled in the art should understand that the combinations of the constituent elements and processes of these embodiments may be modified in various ways, and such modifications are also within the scope of this disclosure.

[0072] Those skilled in the art will recognize that the present disclosure can be implemented in other predetermined forms without changing the technical idea or basic characteristics of the present disclosure. Therefore, it should be understood that the above embodiments are merely illustrative and not restrictive. The scope of the present disclosure is defined by the appended claims rather than by the detailed description. Therefore, it should be understood that all modifications or variations derived from the meaning and scope of the appended claims and their equivalents are within the scope of the present disclosure.

[0073] Although the present disclosure has been shown and described with reference to various embodiments of the present disclosure, those skilled in the art will understand that various changes can be made in form and detail without departing from the spirit and scope of the present disclosure as defined by the appended claims and their equivalents.

Claims

1. A method for identifying a domain name system (DNS) tunnel, the method comprising: Obtain the DNS traffic within a sampling unit time from the input signal; Constructing a DNS sample vector based on the DNS traffic; Providing the DNS sample vector as input to a trained machine learning model; obtaining a model output of the trained machine learning model; and Based on the model output, it is identified whether a DNS tunnel exists in the DNS traffic.

2. The method of claim 1, wherein: The parameters of the DNS sample vector include: the minimum length of the response name, the maximum length of the response name, the average length of the response name, the standard deviation of the length of the response name, the minimum number of labels in the response name, the maximum number of labels in the response name, the average number of labels in the response name, and the standard deviation of the number of labels in the response name.

3. The method of claim 1, wherein: The trained machine learning model is a neural network model.

4. The method of claim 3, wherein: The neural network model includes an input layer, a first hidden layer, a second hidden layer and an output layer.

5. The method of claim 4, wherein: The input layer and the first hidden layer each include a parameter number of neurons of the DNS sample vector; The second hidden layer includes neurons having half the number of parameters of the DNS sample vector; and The output layer includes one neuron.

6. The method according to any one of claims 4 to 5, wherein: The input layer, the first hidden layer, the second hidden layer and the output layer are all connected in a fully connected manner.

7. The method according to any one of claims 4 to 5, wherein: The output layer uses SIGMOID as the activation function, and its range is [-1, 1].

8. The method of claim 1, wherein: The error calculation method of the trained machine learning model is mean square error (MSE).

9. A device for identifying a Domain Name System (DNS) tunnel, the device comprising: Memory, which stores instructions; as well as At least one processor is coupled to the memory and is configured to execute the instructions to perform the method according to any one of claims 1-8.

10. A machine-readable medium comprising instructions, which when executed by at least one processor causes the at least one processor to perform the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • traffic simulation method, traffic simulation device and detection method for DNS tunnel

    CN114048836A

  • APT attack detection method based on threat feature fusion and meta learning

    CN116248367A

  • Abnormal traffic detection method and system based on BERT model

    CN117675351A

  • Method and device for detecting DNS (Domain Name Server) tunnel and electronic equipment

    CN117879855A

  • Malicious domain name automatic detection method and device, equipment and medium

    CN119254517A