<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>A Survey of DNS Tunnelling Detection Techniques Using Machine Learning</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Shiraz Yassine</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Jawad Khalife</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Maroun Chamoun</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Hussein el Ghor</string-name>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>L'Institut National des Télécommunications ET de l'information, Faculty of Engineering, Saint Joseph University Beirut</institution>
          ,
          <country country="LB">Lebanon</country>
        </aff>
      </contrib-group>
      <fpage>63</fpage>
      <lpage>66</lpage>
      <abstract>
        <p>- The Domain Name System (DNS) is an essential network service translating human-friendly host names into numerical IP addresses. Prior to almost any network communication, a communication with a DNS server is, the most likely, needed. For this reason, DNS cyber-attacks are now one of the most challenging threats in the information security community due to its wide availability and the fact that it's not monitored in terms of security - not intended for data transfer. Particularly, DNS tunnelling embedding data in DNS queries and response is receiving a lot of attention in the research field over the last years. Recent studies have focused on DNS tunnelling detection using machine learning. The aim of this paper is to provide a comprehensive survey of some different techniques proposed recently in the literature for detecting DNS tunnels using machine learning, while highlighting on the main findings and comparing their obtained results.</p>
      </abstract>
      <kwd-group>
        <kwd>Domain Name System</kwd>
        <kwd>Cyber-attacks</kwd>
        <kwd>Tunnelling detection</kwd>
        <kwd>Machine Learning</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>I. INTRODUCTION</title>
      <p>
        DNS translates easy memorized domain names to numerical
IP addresses which is an essential service related to network
and Internet Functionality. For this purpose, DNS protocol
uses special message formats and types, like queries and
replies. DNS and communicate on port 53 using usually UDP
and TCP when the request is larger than 512 octets. RFC 1035
[
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]
      </p>
      <p>To determine the requested services (web pages, mail
servers…), 83 DNS record types (2016) can be used.
Common DNS records include: A, PTR, MX, CNAME, TXT,
NS, and SOA records.</p>
      <p>
        A DNS server can be authoritative – holding the DNS
information - for one zone (example: domain.com) or it can be
a local DNS cache serving client DNS queries. DNS queries
are of two types [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]: (i) Recursive: recursion is when a DNS
server query other DNS server on behalf of original DNS
client for name resolution; (ii) Iterative: Forwarded to
authoritative servers starting with ROOT servers. Each server
refers the client to the next server in the chain, until the current
server can fully resolve the request. So, the resolution of
www.exampledomain.com would query a global root server,
then the top-level domain “com” server and finally the
“exampledomain.com” server.
      </p>
      <p>From a security perspective, DNS stands out among most
protocols for covert channels for several reasons.</p>
      <p>First, because DNS is not intended for data transfer, DNS
traffic is often allowed without being inspected by network
security devices and almost ignored in network security
policies, which makes DNS a prone for attacks and misuse.</p>
      <p>Second, DNS includes some flexible fields used by
attackers like TXT record and other.</p>
      <p>
        In 1998 [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ], Data transfer over DNS protocol has been
discovered and was originally designed as a simple way to
bypass the captive portals at the network edge and gain free
Wi-fi access restricted access sites. Currently, transferring data
over DNS poses a serious security risk to all organizations.
      </p>
      <p>
        In 18 December 2017, The Etisalat UAE [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ] headlined the
news; the website was hacked, redirecting its users to a
Chinese site through DNS tunnelling. The intent of the hacker
was to steal user sensitive information. This attack shows that
DNS can be used to attack well reputed organizations without
referring to complex network protocols or advanced traffic
obfuscation techniques.
      </p>
      <p>
        The global DNS threat survey [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ] covering three regions,
has shown that the business sector is taking DNS tunnelling
threats more into consideration where 38% of businesses are
aware of data exfiltration through DNS (24% in 2016) but still
more than the half are not aware of it. On the other hand, 22%
of the organizations were affected with DNS tunnelling (11%
in 2016).
      </p>
      <p>The remaining of this paper is structured as follows. Section
2 deals with DNS tunnelling description, the way data can be
exfiltrated and by which tools; Section 3 highlights DNS
tunnelling detection techniques using machine learning.
Section 4 compares the surveyed methods; and finally, section
5 finally outlines the conclusion.</p>
    </sec>
    <sec id="sec-2">
      <title>II. DNS TUNNELLING</title>
      <p>
        Tunnelling [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ] allows transmission of data using a certain
infrastructure encoding data of other programs and protocols
in DNS queries and responses without alerting any firewalls or
intrusion detection system. The original intention was to
bypass captive portals in Wi-Fi hotspots at airports or hotels to
acquire free internet access.
      </p>
      <p>DNS tunnelling is a client-server model requiring a client to
be compromised through malware, phishing or social
engineering with the only requirement of access to internal
DNS server. At the infected DNS client level, a persistent
backdoor with a DNS Tunnel will thus be established.</p>
      <p>
        DNS tunnels can be used to exfiltrate important and
confidential data from any organizations network (Data
Exfiltration) or in form of Command and control channel [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]
(C&amp;C).
      </p>
      <p>
        C&amp;C is a communication channel between the target host
and the command and control server. It embeds data and
commands in DNS queries and responses. Also, it includes full
remote access of the compromised host. In 2012 [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ], at the
RSA conference, it was one of the most dangerous
cyberattacks.
      </p>
      <p>
        A lot of malware families have been discovered using DNS
tunnelling to hide their communication: Morto [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ], Feederbot
[
        <xref ref-type="bibr" rid="ref7">7</xref>
        ], etc...
      </p>
      <sec id="sec-2-1">
        <title>A. How does it work? Figure 1.DNS tunnelling</title>
        <p>As illustrated in [Fig. 1], DNS tunnelling requires a
compromised client system to have external network
connectivity and a Rogue DNS server controlled by the
malicious user that can act as an authoritative server to execute
the server-side tunnelling and data payload executable
programs. After being infected by a malware, the DNS client
starts issuing recursive DNS queries addressed to a domain
name controlled by the threat actor. The local DNS server then
forwards the queries iteratively to authoritative servers which
should appear as normal to the local firewall. As shown in
Figure 1, sensitive Data “67AC45001DEF34” can be easily
exfiltrated through the DNS query itself back to the malicious
user rogue DNS Server.</p>
        <p>
          There are many tools [
          <xref ref-type="bibr" rid="ref3">3</xref>
          ], [
          <xref ref-type="bibr" rid="ref10 ref8 ref9">8-10</xref>
          ] used to embed data in DNS
queries and responses between the tunnelled client and the
rogue server that can then forward the data to another
destination client.
        </p>
      </sec>
      <sec id="sec-2-2">
        <title>B. Major DNS tunnelling tools</title>
        <p>
          The Most commonly used DNS tools [
          <xref ref-type="bibr" rid="ref7">7</xref>
          ] are: DNS2tcp,
tcpover-DNS, OzymanDNS, Iodine, split brain,
DNScatP/DNScat2, DNScapy...
        </p>
        <p>
          DNScat [
          <xref ref-type="bibr" rid="ref3">3</xref>
          ], released in 2004, is a java-based tool that
allows two hosts to communicate routing all traffic through
DNS.
        </p>
        <p>
          Iodine [
          <xref ref-type="bibr" rid="ref8">8</xref>
          ], released in 2006, is a cross platform
implementation of IPV4 tunnelling data through DNS server.
It’s written in C language and run on many environments such
Linux, windows and others.
        </p>
        <p>
          DNS2tcp [
          <xref ref-type="bibr" rid="ref9">9</xref>
          ] is a network tool able to encapsulate TCP
packets over DNS tunnels. It’s written in C and runs on Linux.
        </p>
        <p>
          OzymanDNS [
          <xref ref-type="bibr" rid="ref3">3</xref>
          ] is a tool used to create a SSH tunnel over
DNS or for file transfer.
        </p>
        <p>Now that we highlighted on the DNS tunnelling technique
and tools, detecting DNS tunnels seems to be a challenging
task for researchers, as we will show in the next section.</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>III. DNS TUNNELLING DETECTION</title>
      <p>As mentioned earlier, the most challenging concern in
today’s business is to keep ahead with the growing and
changing security threats especially the massive rise in threats
such “DNS Tunnelling”.</p>
      <p>
        DNA tunnelling detection techniques can be grouped, as per
Franham [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ], into two categories: Payload analysis and traffic
analysis.
      </p>
      <p>In payload analysis, the analysis will be for one or more
requests and responses for tunnel Indicators. The attributes
used are: size of request and response, entropy of hostnames,
statistical analysis, uncommon record types and policy
violation.</p>
      <p>In traffic analysis, multiple requests and responses will be
analysed over Time. Traffic attributes used here include
among others: volume of DNS per IP address and per domain,
number of hostnames per domain, geographic location of DNS
server, domain history.</p>
      <p>Recently, as a response toward the DNS tunnelling concern,
researchers are tending to use Machine Learning Techniques
(MLTs) to detect tunnelling. As mentioned earlier, MLTs will
be highlighted the most and surveyed in this paper.</p>
      <sec id="sec-3-1">
        <title>C. Machine learning</title>
        <p>Machine learning is a subfield of artificial intelligence
used to understand data structure and fit it into models that can
be used by people. It allows computers to train on data inputs
and statistical features.</p>
        <p>Machine Learning is mostly used for an efficient tunnelling
detection. It provides a way to define normal behaviour in a
network, so it can detect anomalies that indicate the presence
of DNS tunnels. Several MLTs exist: Support Vector Machine
(SVM), Naïve Bayes (NB), Decision Tree (DT), K-nearest
Neighbor (KNN) and others.</p>
      </sec>
      <sec id="sec-3-2">
        <title>D. MLT Used for DNS Tunnel Detection</title>
        <p>Different Machine Learning algorithms are used in the field
of data science classified mainly into two categories: The
Supervised learning and unsupervised learning.</p>
        <p>The Supervised learning is where instances are given with
known labels and it includes algorithms such logistic and
linear regression, classification and support vector machine;
with the latter one, the instances are unlabelled. A well-known
algorithm in unsupervised learning is k-means clustering.</p>
        <p>
          Maurizio Aiello et al. [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ] show how basic classifiers of
supervised learning are used to detect DNS tunnelling. His
approach lies on Bayes classifier exploiting the statistical
features of DNS Messages and detecting the presence of
malicious data by analysing the entire set of DNS server
exchanged information.
        </p>
        <p>The performance evaluation shows that the approach is
reliable and good results are obtained despite the simplicity of
the mechanism.</p>
        <p>
          In [
          <xref ref-type="bibr" rid="ref12">12</xref>
          ], the same work was enhanced by a monitoring
mechanism using the same classifier that looks at statistical
features of protocol message, such as packet inter-arrival times
and of packet sizes instead of focusing on a single one and by
reducing the classification time. As per the authors claim, the
approach was reliable, robust and fast for DNS tunnelling
detection.
        </p>
        <p>
          Anirban Das et al. [
          <xref ref-type="bibr" rid="ref13">13</xref>
          ] addressed DNS tunnelling through a
robust, end-to-end approach to deploy system for detecting
malicious DNS activities.
        </p>
        <p>“Logistic Regression” is the model used to detect data
exfiltration with DNS tunnelling and “K-Means” for the
tunnelling.</p>
        <p>The 2 machine learning models show high detection and
small false positive rate:</p>
        <p>Logistic regression detects exfiltration with very small false
positive rate of 0.189%</p>
        <p>K-means detect Tunnelling with true positive rate of
91.68% and false positive rate of 0.40%.</p>
        <p>
          Jingkun liu et al. [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ] proposed a mechanism deployed on
the recursive DNS using a set of features including:
timeinterval, request packet size, record type and subdomain
entropy. The mechanism works in an off-line stage using
labelled traffic to identify the existence of tunnelled traffic.
        </p>
        <p>To compare the binary mechanism, the authors used 3
algorithms: Support Vector Machine (SVM), Logistical
regression (LR), and Decision Tree (DT) and the results shows
detection accuracy and precision of 99.96%.</p>
        <p>
          Van Thuan Do et al. [
          <xref ref-type="bibr" rid="ref15">15</xref>
          ] addressed DNS tunnelling
detection in mobile networks using machine learning.
        </p>
        <p>Two methods have been selected: OCSVM (One Class
Support Vector Machine) and K-Means. Beside the challenge
of the small size of DNS dataset, the detection using OCSVM
is superior to the one using K-Means especially that K-means
is a cluster classifier that work better when the clusters are
even which is not the case of DNS tunnelling.</p>
        <p>OCSVM with the Radial Basis Function kernel obtained the
higher and best result with 96% F-measure.</p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>IV. COMPARING TECHNIQUES</title>
      <p>
        Few papers in the literature addressed methods comparison.
Nonetheless, a comparative analysis for detecting DNS
tunnelling using Machine learning techniques was presented
by Mahmoud Sammour et al. in [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ] in order to identify the
most accurate classifier. The techniques used are: Support
Vector Machine (SVM), Naïve Bayes (NB) and Decision Tree
(DT). SVM has outperformed the two other classifiers due to
its high performance in handling multiple numbers of class
labels. The two others have performed approximately the same.
      </p>
      <p>SVM achieved 83% F-measure, NB 79% and 78% by DT.</p>
      <p>
        Saeed Shafieian et al. [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ] addressed DNS protocol
exploitation that causes sensitive data exfiltration via
tunnelling.
      </p>
      <p>Signature-based intrusion detection isn’t effective.
Therefore, the authors proposed a technique that employs an
ensemble of machine learning algorithms that are different in
nature. The algorithms used are: Random Forests, K-Nearest
(K-NN) and Multi-layer perception (MLP).</p>
      <p>Results show the following:
•
•
•
•
•
•
•
•</p>
      <p>Ensemble of machine learning classifiers performs
better than single one.</p>
      <p>The Ensemble of RF and Multi-layer perceptron have
near false positive in detecting DNS tunneling.</p>
      <p>Weight of classifier and the combination rule affect the
performance.</p>
      <p>Adding more classifiers can reduce the performance.
SVM has outperformed the NB and DT by achieving
the highest F-measure.</p>
      <p>DNS tunneling detection in Mobile networks using
OCSVM is superior to the one using K-Means.</p>
      <p>Logistic regression and K-Means are used for data
exfiltration and C&amp;C tunnel detection with low false
positive and high detection rate.</p>
      <p>Bayes Classifier of supervised learning can be used as
a reliable and fast DNS tunnelling detector.</p>
      <p>F-Measure
99.6%
Based on the surveyed works in this paper, Table 1
summarizes and compares the main aspects of each methods.
As shown in Table 1, methods tend to use different known
algorithms. Results shows reliable DNS tunneling techniques
using Bayes, K-means and logistic regression. OCSVM is
better than K-Means and SVM is better than Bayes and DT.
Binary classification outperforms SVM, DT and logistic
regression.</p>
      <p>An ensemble of machine learning classifiers performs better
than single one: RF and Multi-layer perceptron have near-zero
false positive.</p>
    </sec>
    <sec id="sec-5">
      <title>V. CONCLUSIONS</title>
      <p>In this paper, we surveyed some of DNS tunnelling
detection techniques using machine learning and the
approaches cover different range of tunnelling detection to
better define the scope of research. With this variety, it is a
challenging task to identify the most suitable classifier, which
would fit the process of detecting DNS tunnelling. Throughout
this survey, we have shown several challenges for researchers
in the field: Results for different machine learning method
don't provide the same performance metrics and use different
datasets.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          <source>[1] RFC 1035</source>
          ,
          <string-name>
            <surname>Domain</surname>
            <given-names>Names</given-names>
          </string-name>
          - Implementation and Specification, P. Mockapetris,
          <source>the Internet Society (November</source>
          <year>1987</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          <article-title>[2] Recursive and Iterative DNS Queries</article-title>
          . http://www.omnisecu.com/tcpip/recursive-and
          <article-title>-iterative-dns-queries</article-title>
          .php
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>G.</given-names>
            <surname>Franham</surname>
          </string-name>
          and
          <string-name>
            <given-names>A.</given-names>
            <surname>Atlasis</surname>
          </string-name>
          ,
          <article-title>"Detecting DNS Tunneling" SANS institute InfoSec Reading Room</article-title>
          . 2013
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>UAE</given-names>
            <surname>Today</surname>
          </string-name>
          <article-title>" Advanced DNS Protection is the need of the hour of Middle East telco operators, in the light of Etisalat website hacking " http://www</article-title>
          .uaetoday.com/news_details.
          <source>asp?newsid=52987</source>
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          <source>[5] 2017 Report - The global DNS threat Survey</source>
          http://www.infosecurityeurope.com/__novadocuments/445925?v=
          <volume>63655</volume>
          <fpage>4315770370000</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>C.</given-names>
            <surname>Mullaney</surname>
          </string-name>
          .
          <article-title>Morto worm sets a (DNS) record</article-title>
          .
          <source>Technical report, Symantec</source>
          ,
          <year>2011</year>
          . http://www.symantec.com/connect/blogs/mortoworm
          <article-title>-sets-dns-record.</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <surname>Christian</surname>
            <given-names>J.</given-names>
          </string-name>
          <string-name>
            <surname>Dietrichyz</surname>
          </string-name>
          , Christian Rossowz, Felix C. Freilingy, Herbert Bos, Maarten van Steen and
          <string-name>
            <surname>Norbert Pohlmannz</surname>
          </string-name>
          , “
          <article-title>On Botnets that use DNS for Command and Control”</article-title>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>Maurizio</given-names>
            <surname>Aiello</surname>
          </string-name>
          ,
          <string-name>
            <surname>Alessio</surname>
            <given-names>Merlo2</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gianluca</surname>
            <given-names>Papaleo</given-names>
          </string-name>
          ,”
          <article-title>Performance Assessment and Analysis of DNS Tunneling Tools”</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <surname>Iodine</surname>
          </string-name>
          . https://code.kryo.se/iodine/
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <fpage>DNS2tcp</fpage>
          . https://tools.kali.org/maintaining-access/
          <year>dns2tcp</year>
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <surname>Maurizio</surname>
            <given-names>Aiello</given-names>
          </string-name>
          , Maurizio Mongelli, Gianluca Papeleo,
          <article-title>"Basic Classifiers for DNS tunneling Detection (</article-title>
          <year>2013</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>M.</given-names>
            <surname>Aiello</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Mongelli</surname>
          </string-name>
          , and
          <string-name>
            <given-names>G.</given-names>
            <surname>Papaleo</surname>
          </string-name>
          ,
          <article-title>"DNS Tunneling detection through statistical fingerprints of protocol messages and machine learning"</article-title>
          . (
          <year>2014</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <surname>Anirban</surname>
            <given-names>Das</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Min-Yi</surname>
            <given-names>Shen</given-names>
          </string-name>
          ,
          <string-name>
            <given-names>Madhu</given-names>
            <surname>Shashanka</surname>
          </string-name>
          and
          <string-name>
            <given-names>Jisheng</given-names>
            <surname>Wang</surname>
          </string-name>
          ,
          <article-title>"Detection of Exfiltration and tunneling over DNS”</article-title>
          . (
          <year>2017</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <surname>Jingkun</surname>
            <given-names>Liu</given-names>
          </string-name>
          ,
          <string-name>
            <given-names>Shuhao</given-names>
            <surname>Li</surname>
          </string-name>
          , Yongzheng Zhang, Jun Xiao,
          <string-name>
            <given-names>Peng</given-names>
            <surname>Chang</surname>
          </string-name>
          and
          <string-name>
            <given-names>Chengwei</given-names>
            <surname>Peng</surname>
          </string-name>
          ,
          <article-title>"Detecting DNS Tunnel through Binary-Classification Based on Behavior Features"</article-title>
          . (
          <year>2017</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <surname>Van Thuan</surname>
            <given-names>Do</given-names>
          </string-name>
          , Paal Engelstad, Boning Feng, and Thanh Van Do,
          <article-title>"Detection of DNS tunneling in Mobile Networks using Machine Learning</article-title>
          . (
          <year>2017</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <surname>Mahmoud</surname>
            <given-names>Sammour</given-names>
          </string-name>
          , Burairah Hussin, Mohd Fairuz Iskandar Othman,
          <article-title>"comparative Analysis for detecting DNS tunneling Using Machine Learning techniques</article-title>
          . (
          <year>2017</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <surname>Saeed</surname>
            <given-names>Shafieian</given-names>
          </string-name>
          ,
          <string-name>
            <given-names>Daniel</given-names>
            <surname>Smith</surname>
          </string-name>
          ,
          <string-name>
            <given-names>and Mohammad</given-names>
            <surname>Zulkernine</surname>
          </string-name>
          ,
          <article-title>"Detecting DNS Tunneling Using Ensemble Learning”</article-title>
          . (
          <year>2017</year>
          )
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>