flâneur — a map of the web's best reading

Machine Learning in Security: Detect DNS Data Exfiltration Using Deep Learning | Splunk

splunk.com · 2,338 words · saved by 1 readers

Since the Domain Name System (DNS) protocol is foundational for internet functionality, DNS traffic is allowed to move through firewalls without much scrutiny unlike HTTPS, FTP and SMTP. Malicious actors have successfully been able to exploit this advantage to transfer data between networks, which is beyond the original intention of DNS protocol. Since the DNS is usually User Datagram Protocol (UDP) in nature, adversaries perform either high throughput tunneling by creating a Command and Control (C2) channel through which data moves reliably and bi-directionally between malware infected client and C2 server or low throughput data exfiltration by sending independent DNS queries containing small data. Data exfiltration can be carried out by outside attackers, where they inject malware into systems using sophisticated techniques like phishing and then the malware orchestrates data exfiltration periodically. Data exfiltration can also be an insider threat, where company employees can carry

Machine Learning in Security: Detect DNS Data Exfiltration Using Deep Learning | Splunk Machine Learning in Security: Detect DNS Data Exfiltration Using Deep Learning Security July 07, 2023 Namratha Sreekanta Since the Domain Name System (DNS) protocol is foundational for internet functionality, DNS traffic is allowed to move through firewalls without much scrutiny unlike HTTPS, FTP and SMTP. Malicious actors have successfully been able to exploit this advantage to transfer data between networks, which is beyond the original intention of DNS protocol. Since the DNS is usually User Datagram Pro

Explore this link on the map →

related reading