DNS covert communication flow generation method based on disturbance factor regulation and control

By collecting DNS hidden communication data, using random forests to evaluate the importance of features and design perturbations, and generating multi-character DNS malicious traffic, the problems of lack of DNS hidden communication traffic data sets and insufficient features are solved, and the accuracy and confrontation ability of the detection system are improved.

CN120301633APending Publication Date: 2025-07-11BEIHANG UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510411145.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-02
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

In the prior art, the lack of DNS hidden communication traffic data sets, insufficient characteristics and low value, resulting in insufficient accuracy and adversarial capabilities of the detection system. The network attack technology variants are fast, making it difficult to predict new attack variants.

Method used

By collecting real data samples of DNS hidden communications, reproducing common tools, obtaining traffic characteristics, using random forests to evaluate the importance of feature, design perturbations, and generating DNS hidden communication traffic, including data slicing, encoding, information embedding and domain name obfuscation, to generate multi-character DNS malicious traffic.

Benefits of technology

Multi-character malicious DNS traffic is generated, which improves file transfer efficiency and concealment, enhances the success rate of data leakage, covers a larger range of DNS hidden communication attack samples, and improves the accuracy and confrontation capabilities of the detection system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120301633A_ABST
    Figure CN120301633A_ABST
Patent Text Reader

Abstract

The invention discloses a DNS covert communication flow generation method based on disturbance factor regulation and control, and relates to the technical field of network security, and the method comprises the steps: 1, collecting an attack sample; step 2, acquiring covert communication flow characteristics; 3, summarizing covert communication disturbance factors and designing a covert communication flow format; 4, configuring a system file; 5, customizing disturbance factor combination, and preparing custom text information as secret stealing data; step 6, based on the secret stealing data, performing data slicing, encoding and information embedding processing, and sending a DNS request; step 7, after sending the DNS request, confusing domain names by adopting a domain name generation algorithm; and step 8, generating DNS covert communication traffic. According to the method provided by the invention, the flow format fields and the disturbance factors are set in the system configuration file, a large amount of data in the DNS request and the response packet are packaged, and a plurality of disturbance factor combinations are provided, so that the multi-feature DNS covert communication flow is generated.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a method for generating DNS covert communication traffic based on regulation of disturbance factors. Background Art

[0002] With the development of Internet of Things technology, many electronic devices, smart life, and smart medical care have been integrated into people's daily lives. Attackers use communication protocols such as HTTP (Hypertext Transfer Protocol) and DNS (Domain Name System) to disguise the transmission process of user private data as the target user's daily communication process, thereby secretly transmitting private information in the user's device. Among them, the HTTP protocol is a dependent protocol for a large amount of malicious traffic, and the detection technology of related HTTP traffic has also become mature, with little room for development.

[0003] The DNS protocol is an important part of daily access activities for network users, and the DNS protocol is often used for domain name resolution rather than information communication. Therefore, traditional intrusion detection systems and network firewalls will not carefully examine whether the DNS traffic passing through is a covert channel or whether it carries secret files in the traffic. Attackers can easily use DNS to transfer data, obtain user data for deeper attacks, or directly sell data for profit. The attack and defense confrontation in the network is a process in which attackers and defenders constantly improve their technology and try to win the confrontation. Attackers can learn the latest detection technology based on current security systems, technical documents, and academic papers, and take the lead in studying the characteristics of malware during the incubation period of the attack to avoid detection by the detection system, while defenders find it difficult to obtain this information in time and take corresponding defensive measures. Therefore, in order to prepare for the DNS covert communication attack in advance, we need to study the traffic characteristics of existing DNS covert communication, predict the DNS covert communication traffic that has not yet appeared, and use the traffic generated to improve the current detection system to provide a deeper level of security for network communication.

[0004] The traffic data set of DNS covert communication may contain some information stolen from the victim host and personal Internet access information such as the victim's IP address. Directly disclosing this type of data set will violate the privacy rights of users. However, removing these sensitive signals from the data set will also damage the data integrity, thus greatly reducing the quality and value of the data set. On the other hand, the desensitized data set will lose some traffic characteristics, resulting in developers being unable to obtain all traffic characteristics. The detection model trained using such a data set as the training set of the detection model will lack the detection basis for DNS covert communication traffic with all characteristics, and the detection strength will decline. At the same time, the network attack technology changes rapidly, and new attack variants often emerge. It is difficult for defenders to predict the emergence of new attack variants from early data sets, and the update speed of the data set is difficult to meet the needs of defenders to update detection technologies. Therefore, how to legally obtain diverse DNS covert communication traffic starting from the attack principle of DNS covert communication is the key to solving the current situation of the lack of DNS covert communication traffic data sets, insufficient characteristics, and low value, and is also the key to improving the accuracy and confrontation ability of the detection system. Summary of the Invention

[0005] The purpose of the present invention is to provide a method for generating DNS covert communication traffic based on the regulation of perturbation factors, so as to solve the problems of the lack of DNS covert communication traffic data sets, insufficient characteristics, and low value existing in the prior art.

[0006] To achieve the above purpose, the present invention provides a method for generating DNS covert communication traffic based on the regulation of perturbation factors, including the following steps:

[0007] Step 1: Collect attack samples by collecting real data samples of DNS covert communication and reproducing common DNS covert communication tools such as DET and DNSExfiltrator;

[0008] Step 2: Based on the attack samples collected in Step 1, obtain the covert communication traffic characteristics by comparing the differences between the DNS covert communication traffic generated by different tools and the normal DNS traffic;

[0009] Step 3: Calculate the importance of different covert communication traffic characteristics through the feature importance evaluation method based on random forest, determine the contribution degree of different characteristics, and summarize the covert communication perturbation factors; design the covert communication traffic format through the statistical DNS covert communication attack samples and their domain name construction formats;

[0010] Step 4: Configure the system files based on the covert communication perturbation factors and the covert communication traffic format in Step 3;

[0011] Step 5: Based on the configuration of the system files, combine custom perturbation factors and prepare custom text information as the stolen data;

[0012] Step 6: Based on the stolen data, perform data slicing, encoding, and information embedding processes, and send a DNS request.

[0013] Step 7: After sending the DNS request, use a domain name generation algorithm to obfuscate the domain name.

[0014] Step 8: Generate DNS covert communication traffic.

[0015] Preferably, the covert communication traffic characteristics in Step 2 include:

[0016] Length of DNS request / response: DNS covert communication needs to transmit data through DNS request messages and response messages, resulting in a longer domain name.

[0017] Proportion of digital characters in the domain name: DNS covert communication encodes the transmitted data in hexadecimal, generating a large number of digits, resulting in a high proportion of digital characters.

[0018] Character frequency in the domain name: The domain names constructed by DNS covert communication do not conform to Zipf's law, and the character distribution is almost uniform.

[0019] Readability of the domain name: The domain names constructed by DNS covert communication have poor readability, strong character randomness, and may use special characters and consecutive consonants, resulting in anomalies in terms of vowels and consonants, stressed characters, etc.

[0020] Resource record type: Different from normal DNS requests that mostly use A, CNAME, AAAA resource record types, DNS covert communication may use a large number of TXT or NULL resource record types.

[0021] Upload / download ratio of the payload: During DNS covert communication, the controlled end needs to upload a large amount of resource data, while the controlling end only sends a small number of commands, resulting in a high upload / download ratio of the payload. In a normal DNS session, the data returned by the server is more than the request information from the client, and the upload / download ratio of the payload is relatively low.

[0022] Total number of data packets: DNS covert communication needs to transmit a large amount of message data, so the total number of data packets is large. In a normal DNS session, it ends with a single parsing task, and the total number of data packets is small.

[0023] DNS request response time interval: During DNS covert communication, the subdomain names of each request will change, and the probability of hitting the local cache is low, resulting in a long DNS request response time interval. In a normal DNS session, due to the local cache mechanism controlled by RTT, the DNS request response interval is relatively short.

[0024] Fully Qualified Domain Name (FQDN) number: When DNS covert communication occurs, the FQDN number within a certain time window will be higher than that contained in normal DNS traffic.

[0025] Preferably, in step 3, the importance of different covert communication traffic characteristics is calculated through a feature importance evaluation method based on random forest, the contribution degree of different features is determined, and the process of summarizing the covert communication disturbance factors is as follows:

[0026] S31. Construct a random forest model; the random forest consists of T decision trees, and the out-of-bag data set D of each tree is recorded during the training process t ;

[0027] S32. Evaluate feature importance; use the MDA method to measure the impact of features by randomly swapping the feature data of samples, specifically as follows:

[0028] For each tree t = 1......T, calculate the accuracy r0 of the regression on D t :

[0029]

[0030] For each feature j = 1......M, randomly swap the feature j of the D t samples to obtain and calculate the accuracy r1 of the regression on :

[0031]

[0032] Calculate the importance score mda(t,j) of feature j on t trees:

[0033]

[0034] For each feature j = 1......M, calculate the importance MDA r (j) of feature j:

[0035]

[0036] Among them, (X i , y i ) represents the sample, X i is the sample input, y i is the sample output, represents the k-th dimensional feature output of X i , represents the sample after randomly swapping the j-th dimensional feature of X i ; R k (X i ) represents the sample X iThe predicted output of the k-th dimensional feature; Denote the sample The predicted output of the k-th dimensional feature; D t Is the out-of-bag sample set of the random tree t; Is the sample set formed after the j-th dimension is swapped; MDA r (j) is the increase value of the out-of-bag sample mean square error after the feature j is randomly swapped; T is the number of random trees in the random forest model;

[0037] S33. Feature importance normalization: Normalize the values of feature importance to compare the relative importance between different features;

[0038] S34. Importance ranking; Rank according to the normalized feature relative importance obtained in S33 to obtain the DNS covert feature importance ranking;

[0039] S35. Design perturbation factors according to the feature importance ranking.

[0040] Preferably, the perturbation factors include:

[0041] Subdomain name length: Encoding or encrypting plaintext data will cause the string to become longer. Therefore, when transmitting more information in DNS queries, a shorter subdomain name length is required to reduce the request length. However, an overly short subdomain name may cause the query request to be rejected or ignored. Therefore, it is crucial to select an appropriate subdomain name length;

[0042] DNS resource record type: Attackers often use MX, CNAME, and TXT records to transmit strings, resulting in abnormal behavior and becoming one of the detection features. Therefore, using the A record as the resource record type for DNS query requests can effectively map IP addresses and remote control instructions to establish an attack connection. During the data leakage stage, the A record can be combined with other multiple resource record types to meet different attack requirements;

[0043] Message sending frequency: During long-term information stealing activities, attackers need to balance the benefits and concealment obtained from the attack. Therefore, they cannot send DNS requests at a high frequency. Overly frequent requests will attract the attention of the server and are easily detected. Therefore, attackers need to maintain a certain message sending frequency while attracting as little attention as possible, which requires analysis and selection according to the specific environment;

[0044] Attack occurrence time: Attackers often choose the most suitable attack time according to the situation of the attack target and the attack purpose. If attackers hope to obtain a larger-scale attack, they may lurk in the victim's host and choose the time when the user is inactive to launch an attack. If attackers hope to obtain immediate attack benefits, they may launch an attack when the user's network activities are frequent;

[0045] DNS server for specified IP: When stealing data, the attacker can use the default DNS server of the controlled host for resolution to reduce abnormal behavior. However, the attacker can also specify the DNS server of an IP for domain name query to avoid registering the C2 server. By incrementing a random number, the attacker can confirm the retransmission and response IPs and avoid the anomaly of "multiple domain names corresponding to one IP address".

[0046] Special information: The attacker combines the stolen data with subdomains using special information to avoid detection and securely transmit the information to the C2 DNS server. This method relies on the UDP transmission feature of DNS to ensure the independence of each query request, thereby increasing the success rate of data stealing.

[0047] Domain name obfuscation: The attacker uses domain name generation technology to generate a large number of pseudo-random malicious domain names with specific statistical characteristics to reduce the probability of being discovered, enhance the security of the botnet, and avoid the characteristic impact on DNS covert communication traffic and command and control traffic by adding perturbation factors, thereby effectively evading blacklists and traditional DGA detection systems.

[0048] Readability of domain names: It refers to the characteristics that are easy for humans to understand and remember. In data breaches, malicious domain names often have high entropy and poor readability. The attacker uses tools such as cloakify factory to convert private data into common strings to reduce entropy and avoid conventional detection, increasing the difficulty of being discovered.

[0049] Preferably, the format design of the covert communication traffic in step 3 is as follows:

[0050] The initial packet format is <task number><file name> <init><Checksum><Domain Name>;

[0051] The format of the data packet containing confidential information is <Task Number><Fragmentation Sequence Number><Confidential Data><Domain Name>;

[0052] The format of the end packet is <Task Number><Fragmentation Sequence Number> <done><Domain name>。

[0053] Preferably, the configuration of the system file in step 4 is specifically as follows: configure the disturbance factors in the configuration file by fields, and the traffic format is implemented by actual coding. Among them, the key field configures the secondary domain name; the target field configures the IP of the client / server or the IP of the DNS server; the special_info field determines whether to carry special information, and the default configuration is to carry special information; the encode-method field determines whether to use cloakify factory for encoding; the domain-len field configures the length of the domain name in the DNS request sent; the AES-KEY field configures the AES encryption key; the max-time-sleep field and the min-time-sleep field determine the message sending frequency; the max-bytes-read field and the min-bytes-read field determine the data shard length; the compression field determines whether to perform compression; the dga field determines whether to use the DGA algorithm to hide the target domain name, and at the same time the dga-type field determines whether to use the time-dependent DGA algorithm, and the dga-type field takes effect when the dga field is 1; after establishing a DNS tunnel between the client and the server, the server remotely controls and accesses the client\etc\host\ file, and adjusts the fifth disturbance factor by modifying the IP of the DNS server. By default, the DNS server with the specified IP is not used, and the default DNS server is adopted; the occurrence time of the disturbance factor attack is determined by the attacker and is not set in the configuration file.

[0054] Preferably, the specific process of step 6 is as follows:

[0055] S61. Construct the DATA_init packet structure according to the designed traffic format and send a DNS request;

[0056] S62. Select a random number within the interval according to the max-time-sleep field and the min-time-sleep field in the configuration file as the sleep time to control the DNS request sending frequency;

[0057] S63. Compress the confidential data and encrypt it using the AES method;

[0058] S64. Randomly take a value within the interval as the shard length according to the max-bytes-read field and the min-bytes-read field in the configuration file, and read the data with the shard length in the confidential file;

[0059] S65. Use the cloakify factory to encode the fragmented confidential data and convert the confidential data into a list of seemingly harmless daily strings;

[0060] S66. According to the designed traffic format, construct the structure of the confidential data packet, embed the encoded confidential data into the domain name, and embed the domain name into the DNS request, and send the DNS request;

[0061] S67. Repeat steps S64 - S65 until all the data to be transmitted has been transmitted;

[0062] S68. According to the designed traffic format, construct the DATA_done packet structure and send the DNS request.

[0063] Preferably, the specific process of confusing the domain name using the domain name generation algorithm in step 7 is as follows:

[0064] Read the dga field in the configuration file. When the dga field is 1 and the dga - type field is ime - dependent, adopt the time - dependent DGA confusion technology. The specific process is as follows:

[0065] S71A. Select the starting index by current minute * 17;

[0066] S72A. Concatenate the following values: year + 0x30, representing one byte; month, representing one byte; day rounded to the domain change frequency, representing one byte; value 0, representing one byte; index, and round the index to a multiple of 2, representing four bytes;

[0067] S73A. XOR the eight bytes generated by concatenation in S72A with a custom four - byte key;

[0068] S74A. Hash the above result using MD5;

[0069] S75A. Traverse the 16 bytes generated after MD5 hashing and generate the second - level domain name based on these 16 bytes;

[0070] S76A. Append the top - level domain name TLD based on the current index;

[0071] S77A. Increment the index, take the result modulo 60 * 17 = 1020, and jump to S72A to repeat the execution;

[0072] Read the dga field in the configuration file. When the dga field is 1 and the dga - type field is time - independent, adopt the time - independent DGA confusion technology; the specific process is as follows:

[0073] S71B. Preset the length of the second-level domain name, the TLD, the seed key, and the character baseline;

[0074] S72B. Customize the character order within the vowel list and the consonant list;

[0075] S73B. Determine the domain name characters based on the characters of the seed key and the character baseline, and splice the second-level domain name. Repeat this step until a second-level domain name of the specified length is generated, splice it with the top-level domain name, and print and output;

[0076] S74B. Loop and execute S73B until the specified number of domain names are generated.

[0077] Therefore, the present invention adopts the above DNS covert communication traffic generation method based on perturbation factor regulation. Starting from the principle of DNS covert communication attacks, it defines the DNS covert communication attacks aimed at data leakage as the research content and defines the meaning of perturbation factors, and has the following beneficial effects:

[0078] (1) Aiming at the problems of lack of DNS covert communication traffic datasets, insufficient features, and low value, the present invention proposes 8 perturbation factors to characterize the DNS covert communication traffic features. By different combinations of perturbation factors in the configuration file, the features of the traffic are modified from the attack principle, covering and generating multi-feature DNS malicious traffic;

[0079] (2) Aiming at the problem of low file transfer efficiency of DNS covert communication for data leakage purposes, the present invention redesigned the traffic transmission format from three aspects: the initial packet, the data theft packet, and the end packet, and set information such as task number, file name, checksum, and shard sequence number to ensure the integrity of file transfer, improving the file transfer efficiency of DNS covert communication;

[0080] (3) To improve the concealment of DNS requests carrying stolen information, the present invention uses the domain name generation algorithm DGA to generate a large number of random domain names, covering up DNS covert communication behaviors, confusing communication patterns and reducing the risk of being discovered, and improving the success rate of data leakage;

[0081] (4) Under the control of the configuration file, the present invention processes the stolen data through data slicing, encoding, and information embedding, etc., embeds the stolen data shards and auxiliary information in the predefined specific domain name structure, generates DNS covert communication traffic for data leakage purposes, improving the concealment and deception during the transmission process, and covering a larger range of DNS covert communication attack traffic samples.

[0082] The technical solutions of the present invention will be further described in detail below through the accompanying drawings and embodiments. Description of the Drawings

[0083] Figure 1 This is the overall flowchart of the DNS covert communication traffic generation method based on perturbation factor regulation in the present invention;

[0084] Figure 2 This is the flowchart for designing the perturbation factors of covert communication in the embodiments of the present invention;

[0085] Figure 3 This is the data encoding flowchart of Cloakify Factory in the embodiments of the present invention. Detailed implementation manners

[0086] The following detailed description of the embodiments of the present invention provided in the drawings is not intended to limit the scope of the claimed invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.

[0087] Please refer to Figures 1 - 3 , the DNS covert communication traffic generation method based on perturbation factor regulation includes the following steps:

[0088] Step 1: Collect attack samples by collecting real data samples of DNS covert communication and reproducing common DNS covert communication tools such as DET and DNSExfiltrator;

[0089] Step 2: Based on the attack samples collected in Step 1, obtain the covert communication traffic characteristics by comparing the differences between the DNS covert communication traffic and the normal DNS traffic generated by different tools; among them, the covert communication traffic characteristics include:

[0090] Length of DNS request / response: DNS covert communication needs to transmit data through DNS request messages and response messages, resulting in longer domain names;

[0091] Proportion of digital characters in the domain name: DNS covert communication encodes the transmitted data in hexadecimal, generating a large number of digits, resulting in a high proportion of digital characters;

[0092] Character frequency in the domain name: The domain names constructed by DNS covert communication do not conform to Zipf's law, and the character distribution is almost uniform;

[0093] Readability of the domain name: The domain names constructed by DNS covert communication have poor readability, strong character randomness, and may use special characters and consecutive consonants, resulting in anomalies in aspects such as vowels and consonants, and stressed characters in the domain name;

[0094] Resource record type: Different from normal DNS requests that mostly use resource record types such as A, CNAME, and AAAA, DNS covert communication may use resource record types such as TXT or NULL in large quantities;

[0095] Upload - download ratio of the payload: During the DNS covert communication process, a large amount of resource data needs to be sent back by the controlled end, while the control end only sends a small number of commands, resulting in a high upload - download ratio of the payload. In a normal DNS session, the data returned by the server is more than the request information of the client, and the upload - download ratio of the payload is relatively low.

[0096] Total number of data packets: DNS covert communication needs to transmit a large number of message data, so the total number of data packets is large. While a normal DNS session ends with a single parsing task, and the total amount of data packets is small.

[0097] DNS request - response time interval: During the DNS covert communication process, the sub - domain names of each request will change, and the probability of hitting the local cache is low, so the DNS request - response time interval is long. In a normal DNS session, due to the local cache mechanism controlled by RTT, the DNS request - response interval time is short.

[0098] Total number of domains (FQDN number): When DNS covert communication occurs, within a certain time window, the total number of domains will be higher than that contained in normal DNS traffic.

[0099] Step 3: Calculate the importance of different covert communication traffic characteristics through the feature importance evaluation method based on random forest, determine the contribution degree of different features, and summarize the disturbance factors of covert communication; design the covert communication traffic format through the statistical DNS covert communication attack samples and their domain name construction formats.

[0100] Among them, the process of calculating the importance of different covert communication traffic characteristics through the feature importance evaluation method based on random forest, determining the contribution degree of different features, and summarizing the disturbance factors of covert communication is as follows:

[0101] S31: Construct a random forest model; The random forest consists of T decision trees, and the out - of - bag data set D of each tree is recorded during the training process. t ;

[0102] S32: Evaluate the feature importance; Use the MDA method to measure the impact of features by randomly swapping the feature data of samples, specifically as follows:

[0103] For each tree t = 1......T, calculate the regression accuracy r0 of D t ;

[0104]

[0105] For each feature j = 1......M, randomly swap the feature j of the D t sample to get and calculate the regression accuracy r1 of ;

[0106]

[0107] Calculate the importance score mda(t, j) of feature j on t trees:

[0108]

[0109] For each feature j = 1......M, calculate the importance MDA r (j):

[0110]

[0111] where (X i , y i ) represents a sample, X i is the sample input, y i is the sample output, represents the output of the k-th dimensional feature of X i ; represents the sample after randomly swapping the j-th dimensional feature of X i ; R k (X i ) represents the predicted output of the k-th dimensional feature of sample X i ; represents the predicted output of the k-th dimensional feature of the sample ; D t is the out-of-bag sample set of the random tree t; is the sample set formed after swapping the j-th dimension; MDA r (j) is the increase in the mean squared error of the out-of-bag samples after feature j is randomly swapped; T is the number of random trees in the random forest model;

[0112] S33. Feature importance normalization: Normalize the values of feature importance to compare the relative importance between different features;

[0113] S34. Importance ranking; Rank according to the normalized feature relative importance obtained in S33 to obtain the DNS hidden feature importance ranking;

[0114] S35. Design perturbation factors according to the feature importance ranking, specifically including:

[0115] Subdomain name length: Encoding or encrypting plaintext data will cause the string to become longer. Therefore, when transmitting more information in DNS queries, a shorter subdomain name length needs to be used to reduce the request length. However, an overly short subdomain name may cause the query request to be rejected or ignored. Therefore, choosing an appropriate subdomain name length is crucial;

[0116] DNS Resource Record Types: Attackers often use MX, CNAME, and TXT records to transmit strings, resulting in abnormal behaviors and becoming one of the detection features. Therefore, using A records as the resource record type for DNS query requests can effectively map IP addresses and remote control instructions to establish attack connections. During the data leakage phase, A records can be combined with various other resource record types to meet different attack requirements;

[0117] Message Sending Frequency: In long-term information stealing activities, attackers need to balance the benefits and concealment of the attack, so they cannot send DNS requests at a high frequency. Overly frequent requests will attract the attention of the server and are easily detected. Therefore, attackers need to maintain a certain message sending frequency while attracting as little attention as possible, which requires analysis and selection according to the specific environment;

[0118] Attack Occurrence Time: Attackers often choose the most suitable attack time based on the situation of the attack target and the attack purpose. If attackers hope to conduct a larger-scale attack, they may lurk in the victim's host and choose to launch the attack during the user's inactive time. If attackers hope to obtain immediate attack benefits, they may launch the attack when the user's network activities are frequent;

[0119] DNS Server of Specified IP: When stealing data, attackers can use the default DNS server of the controlled host for resolution to reduce abnormal behaviors, but they can also specify the DNS server of an IP for domain name query, thereby avoiding registering the C2 server, confirming the retransmission and response IPs through the increment of random numbers, and avoiding the anomaly of "multiple domain names corresponding to one IP address";

[0120] Special Information: Attackers use special information to combine the stolen data with subdomains to avoid detection and securely transmit the information to the C2 DNS server. This method relies on the UDP transmission feature of DNS to ensure the independence of each query request, thereby increasing the success rate of data stealing;

[0121] Domain Name Obfuscation: Attackers use domain name generation technology to generate a large number of pseudo-random malicious domain names with specific statistical characteristics to reduce the probability of being discovered, enhance the security of the botnet, and avoid the characteristic impact on DNS covert communication traffic and command and control traffic by adding perturbation factors, thereby effectively evading blacklists and traditional DGA detection systems;

[0122] Domain Name Readability: It refers to the characteristics that are easy for humans to understand and remember. During data leakage, malicious domain names often have high entropy and poor readability. Attackers use tools such as cloakify factory to convert private data into common strings to reduce entropy and avoid conventional detection, increasing the difficulty of being discovered.

[0123] In the process of designing the format of covert communication traffic, by statistically analyzing the common attack samples and their domain name construction formats, it is found that when attackers design malicious domain names, they will make some minor changes to the domain name construction format according to different attack purposes and requirements, resulting in differences in the actual domain name structure features in attack cases due to different attack sample implementations. However, in any case, the construction of the domain name structure will follow certain rules. For example, core parts such as serial numbers and identifiers will be included in the domain name, and the difference lies in the different regions and positions. Therefore, the design of the covert communication traffic format is as follows:

[0124] The initial packet format is <task number><file name> <init><Checksum><Domain Name>;

[0125] The format of the data packet containing the stolen secrets is <Task Number><Fragmentation Sequence Number><Stolen Secrets><Domain Name>;

[0126] The format of the end packet is <Task Number><Fragmentation Sequence Number> <done><Domain Name>。

[0127] Among them, INIT appears in the initial packet of message transmission, indicating the start of the DNS covert communication process; DONE appears in the last packet of message transmission, indicating the end of the DNS covert communication process.

[0128] In the data packets containing confidential information, a 1-bit task number is adopted and the occurrence of redundant task numbers is reduced in data encapsulation; the fragment sequence number is used to determine the position of the transmission packet in the entire transmission process. When the server receives all DNS requests to restore data information, a checksum is provided to verify the integrity and authenticity of the transmitted file data. Finally, the client encrypts and encodes the original data in segments for transmission, and the server returns the reception status after a segment of data is transmitted. The server can parse part of the DNS covert communication data received, effectively avoiding the situation where information cannot be restored due to unstable network transmission.

[0129] Step 4: Configure the system files based on the covert communication disturbance factors and covert communication traffic format in Step 3; specifically, the configuration of the system files is as follows: the disturbance factors are configured in fields in the configuration file, and the traffic format is implemented by actual encoding. Among them, the key field configures the second-level domain name; the target field configures the client / server IP or the IP of the DNS server; the special_info field determines whether to carry special information, and the default configuration is to carry special information; the encode-method field determines whether to use cloakify factory for encoding; the domain-len field configures the length of the domain name in the sent DNS request; the AES-KEY field configures the AES encryption key; the max-time-sleep field and the min-time-sleep field determine the message sending frequency; the max-bytes-read field and the min-bytes-read field determine the data fragment length; the compression field determines whether to perform compression; the dga field determines whether to use the DGA algorithm to hide the target domain name, and at the same time the dga-type field determines whether to use the time-dependent DGA algorithm, and the dga-type field takes effect when the dga field is 1; after establishing a DNS tunnel between the client and the server, the server remotely controls and accesses the client\etc\host\ file, and adjusts the fifth disturbance factor by modifying the IP of the DNS server. By default, the DNS server with the specified IP is not used, and the default DNS server is adopted; the occurrence time of the disturbance factor attack is determined by the attacker and is not set in the configuration file.

[0130] Step 5: Based on the configuration of the system files, prepare the custom text information as the confidential data by combining custom disturbance factors.

[0131] Step 6: Based on the confidential data, perform data slicing, encoding, and information embedding processes, and send DNS requests. The specific process is as follows:

[0132] S61: Construct a DATA_init packet structure according to the designed traffic format and send a DNS request.

[0133] S62: Select a random number within the range as the sleep time according to the max-time-sleep field and min-time-sleep field in the configuration file to control the DNS request sending frequency.

[0134] S63: Compress the confidential data and encrypt it using the AES method.

[0135] S64: Randomly select a value within the range as the shard length according to the max-bytes-read field and min-bytes-read field in the configuration file, and read the data of the shard length from the confidential file.

[0136] S65: Encode the sliced confidential data using cloakify factory to convert the confidential data into a list of seemingly harmless daily strings. The specific process is as follows:

[0137] S651: Input the file to be encoded file and the key name cipher.

[0138] S652: Check whether the key file exists. If not, end and return an exception message. If it exists, obtain the key file cipher.

[0139] S653: Base64 encode the file file and temporarily save it as file-t.

[0140] S654: Read the temporary file file-t character by character.

[0141] S655: Determine whether the current character is \n. If not, return to execute the previous step. If so, execute the next step.

[0142] S656: Calculate the character index index.

[0143] S657: Select a word replacement according to index in cipher.

[0144] S658: Write to the file character by character.

[0145] S659: Output the encoded file out-file.

[0146] S66. Construct a structure of the data packet containing confidential information according to the designed traffic format, embed the encoded confidential data into the domain name, and embed the domain name into the DNS request, then send the DNS request;

[0147] S67. Repeat steps S64 - S65 until all the data to be transmitted has been transmitted;

[0148] S68. Construct a DATA_done packet structure according to the designed traffic format and send a DNS request.

[0149] Step 7. After sending the DNS request, use the domain name generation algorithm to obfuscate the domain name; the specific process is as follows:

[0150] Read the dga field in the configuration file. When the dga field is 1 and the dga - type field is ime - dependent, adopt the time - dependent DGA obfuscation technology. The specific process is as follows:

[0151] S71A. Select the starting index through the current minute * 17;

[0152] S72A. Concatenate the following values: year + 0x30, representing one byte; month, representing one byte; day rounded to the domain change frequency, representing one byte; value 0, representing one byte; index, and round the index to a multiple of 2, representing four bytes;

[0153] S73A. XOR the eight bytes generated by concatenating in S72A with a custom four - byte key;

[0154] S74A. Perform a hash process on the above result using MD5;

[0155] S75A. Traverse the 16 bytes generated after the MD5 hash process and generate a second - level domain name based on these 16 bytes;

[0156] S76A. Append the top - level domain name TLD based on the current index;

[0157] S77A. Increment the index, take the result modulo 60 * 17 = 1020, and jump to S72A to repeat the execution;

[0158] Read the dga field in the configuration file. When the dga field is 1 and the dga - type field is time - independent, adopt the time - independent DGA obfuscation technology; the specific process is as follows:

[0159] S71B. Preset the length of the second - level domain name, TLD, seed key, and character baseline;

[0160] S72B. Customize the character order within the vowel list and consonant list;

[0161] S73B. Determine the domain name characters based on the characters of the seed key and the character baseline, and splice the second-level domain name. Repeat this step until a second-level domain name of the specified length is generated, splice it with the top-level domain name, and print and output;

[0162] S74B. Loop and execute S73B until the specified number of domain names are generated.

[0163] Step 8. Generate DNS covert communication traffic.

[0164] DNS covert communication: An attack behavior that hides encrypted data in the data field of DNS query and response messages for information transmission and remote control. According to the communication purpose, it can be divided into DNS covert communication technology for command and control purposes and DNS covert communication technology for data leakage purposes. Since the DNS covert communication technology for data leakage purposes has stronger concealment, a wider attack surface, and is more difficult to detect, the present invention mainly studies the generation technology of DNS covert communication for data leakage purposes.

[0165] Perturbation factors: Without changing the malware framework, by controlling and combining different factors, traffic with different characteristics can be generated, thereby bypassing a detection system that assigns a high weight to a certain characteristic. These combined control factors are called perturbation factors.

[0166] Therefore, the present invention adopts the above DNS covert communication traffic generation method based on perturbation factor regulation. By setting the traffic format field and perturbation factors in the system configuration file, as much data as possible is encapsulated in the DNS request and response packets, and multiple combinations of perturbation factors are provided to generate multi-characteristic DNS covert communication traffic. First, collect DNS covert communication attack traffic data, analyze the characteristics of normal DNS traffic and DNS covert communication traffic, compare and summarize their characteristics and influencing factors, and finally form the perturbation factors of DNS covert communication. To improve the integrity and efficiency of file transmission, the present invention redesigned the traffic transmission format from three aspects: the initial packet, the data theft packet, and the end packet, and added information such as task number, file name, checksum, and fragmentation sequence number. Under the control of the configuration file, the attacker converts the data theft data into seemingly harmless daily strings through data slicing, encoding, and information embedding, and hides them in the DNS request. To further enhance the concealment of communication with the target server, the present invention uses the domain name generation algorithm (DGA) to generate a large number of random domain names to cover up the DNS covert communication behavior, confuse the communication mode, and reduce the risk of being discovered. Finally, through corresponding packet processing, request management, and policy response methods, DNS covert communication traffic for data leakage purposes is generated, expanding the coverage of DNS covert communication attack samples.

[0167] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that they can still modify or equivalently replace the technical solutions of the present invention, and these modifications or equivalent replacements cannot make the modified technical solutions deviate from the spirit and scope of the technical solutions of the present invention.< / done> < / init> < / done> < / init>

Claims

1. A method for generating DNS covert communication traffic based on perturbation factor regulation, characterized in that, It includes the following steps: Step 1: Collect attack samples by collecting real data samples of DNS covert communication and reproducing DNS covert communication tools; Step 2: Based on the attack samples collected in Step 1, obtain the covert communication traffic characteristics by comparing the differences between the DNS covert communication traffic and the normal DNS traffic generated by different tools; Step 3: Calculate the importance of different covert communication traffic characteristics through the feature importance evaluation method based on random forest, determine the contribution degree of different characteristics, and summarize the covert communication perturbation factors; Design the covert communication traffic format by statistically analyzing the DNS covert communication attack samples and their domain name construction formats; Step 4: Configure the system files based on the covert communication perturbation factors and the covert communication traffic format in Step 3; Step 5: Based on the configuration of the system files, combine the custom perturbation factors and prepare the custom text information as the confidential data to be stolen; Step 6: Based on the confidential data, perform data slicing, encoding, and information embedding processing, and send DNS requests; Step 7: After sending the DNS requests, use the domain name generation algorithm to obfuscate the domain names; Step 8: Generate DNS covert communication traffic.

2. The method for generating DNS covert communication traffic based on perturbation factor regulation according to claim 1, characterized in that The covert communication traffic characteristics in Step 2 include: the length of DNS requests / responses, the proportion of digital characters in the domain name, the character frequency in the domain name, the readability of the domain name, the resource record type, the upload / download ratio of the payload, the total number of data packets, the DNS request response time interval, and the number of universes.

3. The method for generating DNS covert communication traffic based on disturbance factor regulation according to claim 2, wherein: The process of calculating the importance of different covert communication traffic characteristics through the feature importance evaluation method based on random forest in Step 3, determining the contribution degree of different characteristics, and summarizing the covert communication perturbation factors is as follows: S31. Construct a random forest model; the random forest consists of T decision trees, and the out-of-bag data set D of each tree is recorded during the training process t ; S32: Evaluate the feature importance; use the MDA method to measure the impact of features by randomly swapping the feature data of samples, as follows: For each tree \(t = 1,\cdots,T\), compute \(D\). t The accuracy \(r_0\) of the upper regression: For each feature j = 1......M, for D t randomly swap the feature j of the sample to obtain and calculate the accuracy r1 of the upper regression: Calculate the importance score mda(t,j) of feature j on t trees: For each feature j = 1......M, calculate the importance MDA of feature j r (j): Among them, (X i , y i ) represents a sample, X i is the sample input, and y i is the sample output. represents the k-th dimensional feature output of X i . represents the sample after randomly swapping the j-th dimensional feature of X i ; R k (X i ) represents the predicted output of the k-th dimensional feature of the sample X i . represents the predicted output of the k-th dimensional feature of the sample; D t is the out-of-bag sample set of the random tree t; is the sample set formed after the j-th dimensional swap; MDA r (j) is the increase in the mean squared error of the out-of-bag samples after randomly swapping the feature j; T is the number of random trees in the random forest model. S33: Feature importance normalization: Normalize the values of feature importance to compare the relative importance between different features; S34: Importance ranking; Sort according to the normalized feature relative importance obtained in S33 to obtain the DNS covert feature importance ranking; S35: Design the perturbation factors according to the feature importance ranking.

4. The method for generating DNS covert communication traffic based on perturbation factor regulation according to claim 3, wherein The perturbation factors include: subdomain name length, DNS resource record type, message sending frequency, attack occurrence time, DNS server of the specified IP, special information, domain name obfuscation, and domain name readability.

5. The method for generating DNS covert communication traffic based on perturbation factor regulation according to claim 4, wherein: The design of the covert communication traffic format in Step 3 is as follows: The initial packet format is <task number><file name> <init><Checksum><Domain name>;< / init> The format of the confidential data packet is <Task number><Fragmentation sequence number><Confidential data><Domain name>; The end packet format is <task number><shard number> <done><Domain name>.< / done> 6. The method for generating DNS covert communication traffic based on perturbation factor regulation according to claim 5, wherein The configuration of the system file in Step 4 is specifically as follows: Configure the disturbance factors in the configuration file. The traffic format is implemented by actual coding. Among them, the key field configures the second-level domain name; the target field configures the IP of the client / server or the IP of the DNS server; the special_info field determines whether to carry special information, and the default configuration is to carry special information; the encode-method field determines whether to use cloakify factory for encoding; the domain-len field configures the length of the domain name in the DNS request sent; the AES-KEY field configures the AES encryption key; the max-time-sleep field and the min-time-sleep field determine the message sending frequency; the max-bytes-read field and the min-bytes-read field determine the data shard length; the compression field determines whether to perform compression; the dga field determines whether to use the DGA algorithm to hide the target domain name, and at the same time the dga-type field determines whether to use the time-dependent DGA algorithm, and the dga-type field takes effect when the dga field is 1; after establishing a DNS tunnel between the client and the server, the server remotely controls and accesses the client\etc\host\ file, and adjusts the fifth disturbance factor by modifying the IP of the DNS server. By default, the DNS server with the specified IP is not used, and the default DNS server is adopted; the occurrence time of the disturbance factor attack is determined by the attacker and is not set in the configuration file.

7. The method for generating DNS covert communication traffic based on perturbation factor regulation according to claim 6, wherein The specific process of Step 6 is as follows: S61. Construct the DATA_init packet structure according to the designed traffic format and send a DNS request; S62. Select a random number within the interval according to the max-time-sleep field and the min-time-sleep field in the configuration file and use it as the sleep time; S63. Compress the confidential data and encrypt it using the AES method; S64. Randomly obtain a value within the interval as the shard length according to the max-bytes-read field and the min-bytes-read field in the configuration file, and read the data with the shard length in the confidential file; S65. Use cloakify factory to encode the sharded confidential data and convert the confidential data into a list of daily strings; S66. Construct a confidential data packet structure according to the designed traffic format, embed the encoded confidential data into the domain name, and embed the domain name into the DNS request, and send the DNS request; S67. Repeat Steps S64 - S65 until all the data to be transmitted is transmitted; S68. Construct the DATA_done packet structure according to the designed traffic format and send a DNS request.

8. The method for generating DNS covert communication traffic based on perturbation factor regulation according to claim 7, characterized in that, The specific process of obfuscating the domain name using the domain name generation algorithm in Step 7 is as follows: Read the dga field in the configuration file. When the dga field is 1 and the dga-type field is ime-dependent, adopt the time-dependent DGA obfuscation technology. The specific process is as follows: S71A. Select the starting index through the current minute * 17; S72A. Concatenate the following values: year + 0x30, representing one byte; month, representing one byte; day rounded to the domain change frequency, representing one byte; value 0, representing one byte; index, and round the index to a multiple of 2, representing four bytes; S73A. XOR the eight bytes generated by concatenating in S72A with a custom four-byte key; S74A. Hash the eight bytes generated in S73A using MD5; S75A. Traverse the 16 bytes generated after MD5 hashing and generate the second-level domain name based on these 16 bytes; S76A. Append the top-level domain name TLD based on the current index; S77A. Increment the index, take the result modulo 60 * 17 = 1020, and jump to S72A to repeat the execution; Read the dga field in the configuration file. When the dga field is 1 and the dga-type field is time-independent, adopt the time-independent DGA obfuscation technology; the specific process is as follows: S71B. Preset the second-level domain name length, TLD, seed key, and character baseline; S72B. Customize the character order within the vowel list and consonant list; S73B. Determine the domain name characters with the characters of the seed key and the character baseline and concatenate the second-level domain name. Repeat this step until a second-level domain name of the specified length is generated, concatenate it with the top-level domain name, and print the output; S74B. Loop and execute S73B until the specified number of domain names are generated.