Preview

Труды Института системного программирования РАН

Расширенный поиск

Определение эффективности обнаружения DNS-туннелей при помощи нейронной сети в системе обнаружения вторжений

https://doi.org/10.15514/ISPRAS-2026-38(4)-22

Аннотация

В работе рассматривается метод обнаружения туннелей, реализованных с помощью протокола DNS в сетевом трафике при помощи нейронной сети. Для этого был произведен анализ актуальных методов. Подготовлен набор данных для обучения нейронной сети. Предложенная модель использует на входе последовательность символов, извлеченная из DNS ответа. Обученная модель показала F1-меру близкую к единице. Для проверки работоспособности доработаны модули системы  обнаружения вторжений с открытым исходным кодом Snort3. Обученная модель исполнялась при помощи совместимого модуля LibML. Результаты эксперимента показывают точность близкой к единице и практически полное отсутствие ложных срабатываний. Время обработки DNS пакета с активированным модулем обнаружения при помощи нейронной сети в среднем увеличилось на 13%, а для смешанного трафика, состоящего из различных протоколов время увеличилось на 2%. Анализ экспериментальных данных подтверждает, что использование нейронной сети эффективно дополняет классические средства безопасности, позволяя эффективно обнаруживать скрытые каналы, инкапсулированные в DNS, не оказывая существенного влияния на производительность сигнатурной подсистемы.

Об авторах

Никита Денисович МАРИНИН
Национальный исследовательский университет «Высшая школа экономики»
Россия

Аспирант, Департамент электронной инженерии МИЭМ НИУ ВШЭ. Сфера научных интересов: анализ сетевого трафика с помощью машинного обучения.



Александр Игоревич ГЕТЬМАН
Национальный исследовательский университет «Высшая школа экономики» Институт системного программирования им. В.П. Иванникова РАН НИУ Московский Физико-Технический институт Московский государственный университет им. М.В. Ломоносова
Россия

Кандидат физико-математических наук, старший научный сотрудник ИСП РАН, ассистент ВМК МГУ, доцент ВШЭ и МФТИ. Сфера научных интересов: анализ бинарного кода, восстановление форматов данных, анализ и классификация сетевого трафика.



Список литературы

1. Wang Y., Zhou A., Liao S., Zheng R., Hu R., Zhang L. A comprehensive survey on DNS tunnel detection. Computer Networks, 2021, vol. 197, p. 108322. DOI: 10.1016/j.comnet.2021.108322.

2. Wendzel S., Zander S., Fechner B., Herdin C. Trends and Challenges in Network Covert Channels Countermeasures. Applied Sciences, 2021, vol. 11, no. 4, p. 1641. DOI: 10.3390/app11041641.

3. What Is a DNS Proxy? How Do DNS Proxies Work? Available at: https://www.akamai.com/glossary/what-is-a-dns-proxy, accessed 22.02.2026.

4. Rascagneres P. New FrameworkPOS variant exfiltrates data via DNS requests. Available at: https://www.gdatasoftware.com/blog/2014/10/23942-new-frameworkpos-variant-exfiltrates-data-via-dns-requests, accessed 15.02.2026.

5. Zhang Z., Li H., Zhao Y., Lin C., Liu J. POS: An Operator Scheduling Framework for Multi-model Inference on Edge Intelligent Computing. Proceedings of the 22nd International Conference on Information Processing in Sensor Networks (IPSN ’23). New York, NY, USA: Association for Computing Machinery, 2023, pp. 1-12. DOI: 10.1145/3583120.3586966.

6. Nadler A., Aminov A., Shabtai A. Detection of malicious and low throughput data exfiltration over the DNS protocol. Computers & Security, 2019, vol. 80, pp. 36-53. DOI: 10.1016/j.cose.2018.09.006.

7. Qi C., Chen X., Xu C., Shi J., Liu P. A Bigram based Real Time DNS Tunnel Detection Approach. Procedia Computer Science, 2013, vol. 17, pp. 852-860. DOI: 10.1016/j.procs.2013.05.109.

8. Amirov N., Isik B., Tuncer B., Bahtiyar Ş. DNS Tunneling: Threat Landscape and Improved Detection Solutions. DNS Tunneling, 2025. DOI: 10.1007/978-3-031-91548-4_5.

9. Sammour M., Othman M.F.I., Hassan A., Bhais O., Talib M.S. Advanced DNS tunneling detection: a hybrid reinforcement learning and metaheuristic approach. Frontiers in Computer Science, 2026, vol. 7. Article 1626646. DOI: 10.3389/fcomp.2025.1626646.

10. Lal A., Prasad A., Kumar A., Kumar S. DNS-Tunnet: A Hybrid Approach for DNS Tunneling Detection. 2022 4th International Conference on Advances in Computer Technology, Information Science and Communications (CTISC), 2022, pp. 1-6.

11. Al-Ibraheemi F.A., AL-Ibraheemi S., Amintoosi H. A hybrid method of genetic algorithm and support vector machine for DNS tunneling detection. International Journal of Electrical and Computer Engineering, 2021, vol. 11, no. 2, pp. 1666-1674. DOI: 10.11591/ijece.v11i2.pp1666-1674.

12. Бубнов Я.В. Модели и алгоритмы для обнаружения сетевых атак на основе анализа характеристик DNS-запросов: автореф. дисс. канд. техн. наук: 05.13.19. Минск: БГУИР, 2021. 21 с.

13. Gwon H., Lee C., Keum R., Choi H. Network Intrusion Detection based on LSTM and Feature Embedding. DOI: 10.48550/arXiv.1911.11552.

14. DNS-Tunnel-Datasets: tunnel. Available at: https://github.com/ggyggy666/DNS-Tunnel-Datasets/tree/main/tunnel, accessed 07.02.2026.

15. Gao G., Niu W., Gong J., Gu D., Li S., Zhang M., Zhang X. GraphTunnel: Robust DNS Tunnel Detection Based on DNS Recursive Resolution Graph. IEEE Transactions on Information Forensics and Security, 2024, vol. 19, pp. 7705-7719. DOI: 10.1109/TIFS.2024.3443596.

16. Ekman E. iodine. Available at: https://github.com/yarrick/iodine, accessed 07.08.2026.

17. dns2tcp. Kali Linux Tools. Available at: https://www.kali.org/tools/dns2tcp/, accessed 07.08.2026.

18. dnscapy. Google Code Archive. Available at: https://code.google.com/archive/p/dnscapy/, accessed 07.08.2026.

19. Nussbaum L. tuns. Available at: https://github.com/lnussbaum/tuns, accessed 07.08.2026.

20. dnscat2. Kali Linux Tools. Available at: https://www.kali.org/tools/dnscat2/, accessed 07.08.2026.

21. Chen S., Lang B., Liu H., Li D., Gao C. DNS covert channel detection method using the LSTM model. Computers & Security, 2021, vol. 104, p. 102095. DOI: 10.1016/j.cose.2020.102095.

22. Liu C., Dai L., Cui W., Lin T. A Byte-level CNN Method to Detect DNS Tunnels. 2019 IEEE 38th International Performance Computing and Communications Conference (IPCCC), 2019, pp. 1-8. DOI: 10.1109/IPCCC47392.2019.8958714.

23. Module: tf.lite. TensorFlow v2.16.1. Available at: https://www.tensorflow.org/api_docs/python/tf/lite, accessed 07.08.2026.

24. Snort 3.0 Team. snort3/libml. Available at: https://github.com/snort3/libml, accessed 07.08.2026.

25. Chen T., Guestrin C. XGBoost: A Scalable Tree Boosting System. Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (KDD ’16). New York, NY, USA: Association for Computing Machinery, 2016, pp. 785-794. DOI: 10.1145/2939672.2939785.

26. Pettersson J., Falkman P. Comparison of LSTM, Transformers, and MLP-mixer neural networks for gaze based human intention prediction. Frontiers in Neurorobotics, 2023, vol. 17, p. 1157957. DOI: 10.3389/fnbot.2023.1157957.

27. Zhao Y., Wang G., Tang C., Luo C., Zeng W., Zha Z.-J. A Battle of Network Structures: An Empirical Study of CNN, Transformer, and MLP. DOI: 10.48550/arXiv.2108.13002.

28. Abukhousa E., Zonouz S., Meliopoulos A.P.S. Latency-Aware Deep Learning Benchmark for Real-Time Cyber-Physical Attack and Fault Classification in Inverter-Dominated Power Grids. 2026 IEEE/PES Transmission and Distribution Conference and Exposition (T&D), 2026, pp. 1-5.

29. Pratiwi H., Windarto A.P., Susliansyah S., Aria R.R., Susilowati S., Rahayu L.K., Fitriani Y., Merdekawati A., Rahadjeng I.R. Sigmoid Activation Function in Selecting the Best Model of Artificial Neural Networks. Journal of Physics: Conference Series, 2020, vol. 1471, no. 1, p. 012010. DOI: 10.1088/1742-6596/1471/1/012010.

30. Kingma D.P., Ba J. Adam: A Method for Stochastic Optimization. DOI: 10.48550/arXiv.1412.6980.

31. Abualghanam O., Alazzam H., Elshqeirat B., Qatawneh M., Almaiah M.A. Real-Time Detection System for Data Exfiltration over DNS Tunneling Using Machine Learning. Electronics, 2023, vol. 12, no. 6, p. 1467. DOI: 10.3390/electronics12061467.

32. Johnson R., Zhang T. Effective Use of Word Order for Text Categorization with Convolutional Neural Networks. DOI: 10.48550/arXiv.1412.1058.

33. Kim Y. Convolutional Neural Networks for Sentence Classification. DOI: 10.48550/arXiv.1408.5882.

34. TextConvoNet: a convolutional neural network based architecture for text classification. Available at: https://pmc.ncbi.nlm.nih.gov/articles/PMC9589611/, accessed 21.03.2026.

35. Srivastava N., Hinton G., Krizhevsky A., Sutskever I., Salakhutdinov R. Dropout: A Simple Way to Prevent Neural Networks from Overfitting. Journal of Machine Learning Research, 2014, vol. 15, no. 56, pp. 1929-1958. DOI: 10.5555/2627435.2670313.

36. Baldi P., Sadowski P. The Dropout Learning Algorithm. Artificial Intelligence, 2014, vol. 210, pp. 78-122. DOI: 10.1016/j.artint.2014.03.008.

37. Snort 3.0 Team. snort3/snort3. Available at: https://github.com/snort3/snort3, accessed 07.08.2026.

38. What are Community Rules? Available at: https://www.snort.org/faq/what-are-community-rules, accessed 16.02.2026.

39. Adiwal S., Rajendran B., Shetty D.P., Sudarsan S.D. DNS Intrusion Detection (DID) – A SNORT-based solution to detect DNS Amplification and DNS Tunneling attacks. Franklin Open, 2023, vol. 2, p. 100010. DOI: 10.1016/j.fraope.2023.100010.

40. Thorarensen C. A Performance Analysis of Intrusion Detection with Snort and Security Information Management: Independent thesis, Advanced level, degree of Master (Two Years). Linköping: Linköping University, Department of Computer and Information Science, Database and Information Techniques, 2021, 84 p. Available at: https://urn.kb.se/resolve?urn=urn:nbn:se:liu:diva-177602, accessed 07.08.2026.

41. Freeman E.A., Moisen G.G. A comparison of the performance of threshold criteria for binary classification in terms of predicted prevalence and kappa. Ecological Modelling, 2008, vol. 217, no. 1, pp. 48-58. DOI: 10.1016/j.ecolmodel.2008.05.015.

42. Stultz B. Talos launching new machine learning-based exploit detection engine. Snort Blog, 2024. Available at: https://blog.snort.org/2024/03/talos-launching-new-machine-learning.html, accessed 11.05.2026.

43. Hyperscan. Intel Hyperscan Documentation. Available at: https://intel.github.io/hyperscan/, accessed 11.05.2026.

44. IDS 2017. Datasets. Research. Canadian Institute for Cybersecurity. University of New Brunswick. Available at: https://www.unb.ca/cic/datasets/ids-2017.html, accessed 07.02.2026.

45. Wang X., Hong Y., Chang H., Park K., Langdale G., Hu J., Zhu H. Hyperscan: A Fast Multi-pattern Regex Matcher for Modern CPUs. Proceedings of the 16th USENIX Conference on Networked Systems Design and Implementation (NSDI ’19). USA: USENIX Association, 2019, pp. 631-648.


Рецензия

Для цитирования:


МАРИНИН Н.Д., ГЕТЬМАН А.И. Определение эффективности обнаружения DNS-туннелей при помощи нейронной сети в системе обнаружения вторжений. Труды Института системного программирования РАН. 2026;38(4):123-142. https://doi.org/10.15514/ISPRAS-2026-38(4)-22

For citation:


MARININ N.D., GETMAN A.I. Evaluating the Effectiveness of DNS Tunnel Detection Using a Neural Network in an Intrusion Detection System. Proceedings of the Institute for System Programming of the RAS (Proceedings of ISP RAS). 2026;38(4):123-142. (In Russ.) https://doi.org/10.15514/ISPRAS-2026-38(4)-22



Creative Commons License
Контент доступен под лицензией Creative Commons Attribution 4.0 License.


ISSN 2079-8156 (Print)
ISSN 2220-6426 (Online)