Machine Learning in Security: Detect DNS Data Exfiltration Using Deep Learning | Splunk
Since the Domain Name System (DNS) protocol is foundational for internet functionality, DNS traffic is allowed to move through firewalls without much scrutiny unlike HTTPS, FTP and SMTP. Malicious actors have successfully been able to exploit this advantage to transfer data between networks, which is beyond the original intention of DNS protocol. Since the DNS is usually User Datagram Protocol (UDP) in nature, adversaries perform either high throughput tunneling by creating a Command and Control (C2) channel through which data moves reliably and bi-directionally between malware infected client and C2 server or low throughput data exfiltration by sending independent DNS queries containing small data. Data exfiltration can be carried out by outside attackers, where they inject malware into systems using sophisticated techniques like phishing and then the malware orchestrates data exfiltration periodically. Data exfiltration can also be an insider threat, where company employees can carry
Machine Learning in Security: Detect DNS Data Exfiltration Using Deep Learning | Splunk Machine Learning in Security: Detect DNS Data Exfiltration Using Deep Learning Security July 07, 2023 Namratha Sreekanta Since the Domain Name System (DNS) protocol is foundational for internet functionality, DNS traffic is allowed to move through firewalls without much scrutiny unlike HTTPS, FTP and SMTP. Malicious actors have successfully been able to exploit this advantage to transfer data between networks, which is beyond the original intention of DNS protocol. Since the DNS is usually User Datagram Pro
Explore this link on the map →related reading
- Machine Learning in Security: Detect Suspicious TXT Records Using Deep Learning | Splunksplunk.com
- Machine Learning in Security: Deep Learning Based DGA Detection with a Pre-trained Model | Splunksplunk.com
- Security incident disclosure — July 2026huggingface.co
- Model-Assisted Threat Hunting (M-ATH) with the PEAK Framework | Splunksplunk.com
- Machine Learning in Security: Detecting Suspicious Processes Using Recurrent Neural Networks | Splunksplunk.com
- Learn how easy is to bypass firewalls using DNS tunneling (and also how to block it) | by Roger Galobardes | Mediummedium.com
- Self-exfiltration is a key dangerous capabilityaligned.substack.com
- Anomalies detected by the Microsoft Sentinel machine learning engine | Microsoft Learnlearn.microsoft.com
- Transforming Data Security with AI-Powered Classification - Palo Alto Networks Blogpaloaltonetworks.com
- PerfectData Software Abuse and Account Takeover Risksdarktrace.com
- D3FEND Matrix | MITRE D3FEND™d3fend.mitre.org
- Intrusion Detection | Computer Securitytextbook.cs161.org