Detection of DNS tunneling in mobile networks using machine learning
Journal article, Peer reviewed
MetadataShow full item record
Original versionDo VT, Engelstad P.E., Feng B, Do VTDO. Detection of DNS tunneling in mobile networks using machine learning. Lecture Notes in Electrical Engineering. 2017;424:221-230 http://dx.doi.org/10.1007/978-981-10-4154-9_26
Lately, costly and threatening DNS tunnels on the mobile networks bypassing the mobile operator’s Policy and Charging Enforcement Function (PCEF), has shown the vulnerability of the mobile networks caused by the Domain Name System (DNS) which calls for protection solutions. Unfortunately there is currently no really adequate solution. This paper proposes to use machine learning techniques in the detection and mitigation of a DNS tunneling in mobile networks. Two machine learning techniques, namely One Class Support Vector Machine (OCSVM) and K-Means are experimented and the results prove that machine learning techniques could yield quite efficient detection solutions. The paper starts with a comprehensive introduction to DNS tunneling in mobile networks. Next the challenges in DNS tunneling detections are reviewed. The main part of the paper is the description of proposed DNS tunneling detection using machine learning.