Proceedings 2024 Network and Distributed System Security Symposium 2024
DOI: 10.14722/ndss.2024.24388
|View full text |Cite
|
Sign up to set email alerts
|

Information Based Heavy Hitters for Real-Time DNS Data Exfiltration Detection

Yarin Ozery,
Asaf Nadler,
Asaf Shabtai

Abstract: Data exfiltration over the DNS protocol and its detection have been researched extensively in recent years. Prior studies focused on offline detection methods, which although capable of detecting attacks, allow a large amount of data to be exfiltrated before the attack is detected and dealt with. In this paper, we introduce Information-based Heavy Hitters (ibHH), a real-time detection method which is based on live estimations of the amount of information transmitted to registered domains. ibHH uses constant-si… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...

Citation Types

0
0
0

Year Published

2024
2024
2024
2024

Publication Types

Select...
2
1

Relationship

0
3

Authors

Journals

citations
Cited by 3 publications
references
References 40 publications
(83 reference statements)
0
0
0
Order By: Relevance