<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Technique for Cyberattacks Detection Based on DNS Traffic Analysis</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Sergii Lysenko</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Kira Bobrovnikova</string-name>
          <email>kirabobrovnikova@gmail.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Oleg Savenko</string-name>
          <email>savenko_oleg_st@ukr.net</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Roman Shchuka</string-name>
          <email>schuka.roman@gmail.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Khmelnitsky National University</institution>
          ,
          <addr-line>Khmelnitsky</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>Today, with the rapid spread of computer systems and information technology, as well as their integration into the global Internet, cyberattacks and malware are one of the main types of cybercrime. The damage they cause when they infect network hosts can range from a slight increase in outbound traffic to a complete network malfunction or loss of critical data. The paper presents a new technique for cyberattacks detection based on DNS traffic analysis. It enables the proactive malicious requests detecting in corporate area networks based on DNS protocol, and is aimed to identify and block the malicious domains and DND data deletion requested by the attackers. The process of malicious requests detection is based on the use of "isolation forest" algorithm, which allows to detect the anomalies in DNS data exchange. Based on the general data deletion scheme, an anomaly of DNS traffic is observed when it is used for data exchange. The anomaly in the DNS traffic is detected due to analysis of the set of features concerning the requests and responses that may indicate the attack presence in the network.</p>
      </abstract>
      <kwd-group>
        <kwd>Cyberattack</kwd>
        <kwd>DNS</kwd>
        <kwd>Network traffic</kwd>
        <kwd>Network</kwd>
        <kwd>Isolation forest</kwd>
        <kwd>Cybersecurity</kwd>
        <kwd>Computer system</kwd>
        <kwd>Host</kwd>
        <kwd>Malicious traffic</kwd>
        <kwd>Attacks Detection</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>Introduction</title>
      <p>One of the main signs of the society development is the growth of dependence on the
quality and reliability of computer systems used in all fields of human activity. The
corresponding strengthening of the strategic orientation of information resources
necessitates the increase of requirements to the level of the cybersecurity. However,
there are cases of violations of the information security system. The problem is
exacerbated by the fact that the peculiarities of the global network and the Internet allow
attackers to implement long-term, massive cyberattacks on critical infrastructure, and
the timely application of adequate security measures is greatly hindered by the
imperfection of attack detection systems.</p>
      <p>Copyright © 2020 for this paper by its authors. Use permitted under Creative Commons License Attribution 4.0 International (CC BY 4.0).</p>
      <p>
        The development of information technology necessitates the growth of
vulnerabilities, threats and cyberattacks to various computer systems. According to resources
devoted to the prevention, detection and removal of malware and spam report about
the great number of new cyberattacks [
        <xref ref-type="bibr" rid="ref1 ref2">1, 2</xref>
        ]. One of the ways to infect the computer
systems is the usage of the public DNS servers as they are employed for faster web
browsing or censorship bypassing and are open to anyone. Such situation requires the
development of a new more efficient techniques and approaches for the cyberattacks
detection based on DNS traffic analysis [
        <xref ref-type="bibr" rid="ref3 ref4 ref5">3-5</xref>
        ].
2
      </p>
    </sec>
    <sec id="sec-2">
      <title>Related works</title>
      <p>Today, a number of techniques are developed for the detection of cyberattacks which
use the DNS traffic.</p>
      <p>
        In [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ] a DNS Anomaly Detection Visual Platform, provides a novel visualization
that depicts on-line DNS traffic, and a one-class classifier that deals with traffic
anomaly detection, is presented. Due to the highly dynamic nature of DNS traffic, a
proposed classification method continuously updates what counts as normal behavior;
it has been successfully tested on synthetic attacks, with an 83% of the area under the
curve.
      </p>
      <p>
        In [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ] the technique for MitM-attacks detection called DNSwitch is described. The
utility is able to detect a DNS-spoofing type attack.
      </p>
      <p>
        In [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ] an efficient detection method of suspicious DNS traffic by resolver
separation per application program is presented. Based on that almost all kinds of software
including malware use DNS name resolution, in the pro-posed method, the DNS
queries will be forwarded to different DNS full resolver per application program. The
DNS queries from unknown application programs can be detected since there will be
only little DNS traffic need to be analyzed compare to the whole network traffic. The
evaluation results confirmed that the proposed method can precisely forward the DNS
queries based on the application programs correctly.
      </p>
      <p>
        In [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ] a new filtering approach called “The Gunner System”. The approach
involves rule-based Domain Name System (DNS) features for detecting botnets.
      </p>
      <p>
        In [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ] a method for detecting malware infected computers by monitoring
unintended DNS traffic on wireless networks by collaboration with DHCP server. By
deploying the proposed system on campus wireless networks, computers within
DHCP configured environment can be detected when they are infected by some types
of malware and it attempts to communicate with the corresponding C&amp;C servers
using DNS protocol. In [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ] a study aimed to detect and reduce the effects of DNS
amplification attacks in SDN-based with the developed system. This system aims to
monitor the variations in the amplification factor and TTL header to initiate
mitigation and sustain the victim's life. It also ensures that legitimate packets are not
suspected in the process. In doing so, it is aimed to generate alarms and mitigation by
using the central management feature of SDN, by writing the metrics into a time
series database immediately. Experimental results show that this system can be used
SDN-based networks and prevent an attack in reactively.
      </p>
      <p>
        In [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ] an IoT router that verifies the DNS traffic originated from IoT devices and
performs the detection of IoT devices that are consulting unauthorized DNS servers is
proposed. In [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ] a state-of-the-art of systems that utilized passive DNS traffic for the
purpose of detecting malicious behaviors on the Internet is presented. The paper
demonstrates the feasibility of the threat detection prototype through real-life
examples, and provide further insights for future work toward analyzing DNS traffic in
near real-time. In [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ] a system REMeDy that assists operators to identify the use of
rogue DNS resolvers in their networks. REMeDy is a completely automatic and
parameter-free system that evaluates the consistency of responses across the resolvers
active in the network. It operates by passively analyzing DNS traffic and, as such,
requires no active probing of third-party servers. REMeDy is able to detect resolvers
that manipulate answers, including resolvers that affect unpopular domains.
      </p>
      <p>
        In [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ] the issue of DNS-based data exfiltration proposing a detection and
mitigation method leveraging the Software-Defined Network (SDN) architecture is
presented. Popular DNS data exfiltration attacks and current exfiltration detection
mechanisms are analyzed to generate a feature-set for DNS data exfiltration detection. The
DNSxD application is presented and its performance evaluated in comparison with
the current exfiltration detection mechanisms.
      </p>
      <p>
        Paper [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ] proposes a method to detect two primary means of using DNS for
malicious purposes. The machine learning models to detect information exfiltration from
compromised machines and the establishment of command &amp; control servers via
tunneling are developed and validated. It is able to detect a malware used in several
recent APT attacks.
      </p>
      <p>In [17] a targeted DNS spoofing attack that exploits a vulnerability present in
DHCP server-side IP address conflict detection technique to prevent a genuine DHCP
server from offering network parameters is proposed. Paper discusses how proposed
attack can target even a single victim client also without affecting other clients.</p>
      <p>The Domain Name System Security Extensions (DNSSEC) is a specification
which provides extensions and modifications that add data origin authentication and
data integrity to the Domain Name System. But DNSSEC extension has a number of
disadvantages and limitations and has seen poor deployment thus far and not
intended to prevent a wide range of cyberattacks with usage of DNS [18-19].</p>
      <p>The mentioned above methods for the malicious DNS traffic detecting
demonstrated the limitation of the types of the network attacks’ detection, as the involve not
enough features of the malicious traffic behavior. On the other hand, mentioned
techniques have in some cases low detection efficiency and high false positives.</p>
      <p>That why there is strong need in new for the cyberattacks detection techniques
based on DNS traffic analysis.
3</p>
    </sec>
    <sec id="sec-3">
      <title>Technique for Cyberattacks Detection Based on DNS Traffic</title>
    </sec>
    <sec id="sec-4">
      <title>Analysis</title>
      <p>In order to solve mentioned problems, a new technique for cyberattacks detection
based on DNS traffic analysis is proposed. It enables the proactive malicious requests
detecting in corporate area networks based on DNS protocol, and is aimed to identify
and block the malicious domains and DND data deletion requested by the attackers.</p>
      <p>The method is based on detecting anomalies in DNS data exchange.</p>
      <p>An anomaly of DNS traffic is observed when attacks use them for data exchange.
It is suggested that domains used to exchange data through DNS protocol are
characterized by the set of features concerning the requests and responses that may indicate
the attack presence in the network. Detection of attacks, that use DNS traffic, is based
on the analysis of a certain domain.</p>
      <p>The process of malicious requests detection is based on the use of "isolation
forest" algorithm, which allows the anomalies detection [20] and consists of two main
phases: training and detection.</p>
      <p>The training phase includes the following steps:
1. Knowledge formation about benign requests by the users, which use the DNS
data exchange, based on benign traffic samples.</p>
      <p>2. Knowledge presentation as the set of feature vectors.</p>
      <p>3. Construction of the "isolated trees" structures based on the feature vectors of
based on benign traffic samples.</p>
      <p>4. Passing though the "isolated trees" structures for each benign traffic samples in
the test set, and calculation of the "anomaly score" using the isolated forest algorithm.</p>
      <p>The detection phase includes the steps:
1. Monitoring of the network in order to gather the features that may indicate the
attack presence.</p>
      <p>2. Formation of the set of feature vectors.</p>
      <p>3. Defining as an "anomaly" the feature vector whose estimation exceeds a
predetermined threshold, depending on the domain to which the analysis is applied.
4. Blocking the execution of malicious requests in the computer system.</p>
      <p>The method allows its implementation in DNS servers, which are not necessarily
intended for detection, as long as they support DNS traffic logging and domain
blacklisting (as shown in fig. 1).</p>
      <sec id="sec-4-1">
        <title>Usage of the Isolation Forest Algorithm for the Attacks Detection</title>
        <p>The Isolation Forest algorithm allows to detected the anomalies by the recursively
generating partitions on a data sample by randomly selecting an attribute and then
randomly selecting a split value for an attribute between the minimum and maximum
values allowed for that attribute. To detect the anomaly, the data represented by the
tree structure, named isolated tree, is recursively distributed. Then the number of
sections required to isolate the point is interpreted as the length of the path within the
tree to reach the terminating node, starting from the root [20].</p>
        <p>The main advantages of the isolation forest algorithm are a low linear time
complexity and a small memory requirement. It is able to deal with high dimensional
data with irrelevant attributes, and is able to perform the training with or without
anomalies in the training set. In addition, algorithm is able to provide detection results
with different levels of granularity without the retraining procedure [21].</p>
        <p>Let us assume Ϙ = {ϙ1,…,ϙn} as a set of d-dimensional points, where each point is
a feature vector, that describes malicious DNS traffic.</p>
        <p>In order to detect the malicious requests, it is necessary to construct data structures
with such properties: for each node T in a tree, where T is either an external node
without a child, or an internal node, or exactly with two child nodes (Tl, Tr); node T
consists of an attribute q and a value for splitting p such that q &lt;p determines the
transition of the data point to Tl or Tr.</p>
        <p>The resulting set of feature vectors of malicious DNS traffic, represented by the
points, is recursively divides Ϙ by randomly selection of the attribute q and division
of the value p until any node has only one instance or all data in the node has no equal
values. Then, in the constructed tree, each point in Ϙ is isolated at one of the external
nodes. Anomalous points (malicious traffic detected) are those characterized by a
shorter path length on a tree, where the path length h(ϙi) of the point ϙi∈Ϙ is defined
as the number of edges ϙi extending from the root node to reach the external node.</p>
        <p>In order to evaluate the anomaly score of the analyzed data the observation that the
isolated tree structure is equivalent to the structure of a binary search tree (BST) is
taken into account. Thus, the estimation of the average value h (ϙ) for the external
nodes is the same as for the unsuccessful BST search:
where n - the testing data size;
m - the size of the sample set and H is the harmonic number, which can be
estimated by , where is the Euler-Mascheroni constant;
c(m) represents the average of h(ϙ) given m.</p>
        <p>In order to normalize the value of h(ϙ) and to perform the anomaly score
evaluation for a given sample ϙ we can use equation:
(1)
where E(h(ϙ)) is the average value of h(ϙ) from the set of generated isolated trees.</p>
        <p>It worth mentioning, that note that for any given traffic sample ϙ:
3.2</p>
      </sec>
      <sec id="sec-4-2">
        <title>Data Gathering</title>
        <p>At this stage the data gathering is performed. DNS-traffic is to be gathered and saved
as DNS-logs files. Each DNS-log file describes DNS-traffic during the specified time
window α. Each i-th DNS-log string can be presented as the tuple:
,
(3)
де t – time-stamp;
MAC – MAC-address of infected host;
d – the full queried domain name;</p>
        <p>– the set of the resources records in the answer section of the
DNSrespond, NA – the number of the resources records; for example, a set of the A-records
values (or an empty string in the situation of the NXDOMAIN answer, when the
requested domain name does not exist);
Qr – query type, for example A, NS, PTR etc.</p>
        <p>Presented in a such way DNS-logs strings are to be grouped by the primary domain
name:
where dprim – the primary domain for some domain name;
funcg – a group function for the DNS-logs strings concerning the primary domain
name and time for data gathering;
Rd – a set of the DNS-logs strings for each domain name, grouped by the primary
domain name;
n – a number of the data samples which are to be classified.
3.3</p>
      </sec>
      <sec id="sec-4-3">
        <title>Features Exfiltration</title>
        <p>The feature extraction is performed during the time window α:
∈
, ∈
(4)
where funce – a feature extraction function.</p>
        <p>Feature vector can be presented as follow:
,
(6)
where ∈ , – set of feature vectors;</p>
        <p>– a total number of feature vectors;
Nf – a total number of features;
f1 – the domain name length;
f2 – the number of the unique symbols in the domain name;
f3 – the longest meaningful word length over domain name length average;
f4 – the value of the domain name’s entropy;
f5 – TTL-periods (mode);
f6 – TTL-periods (median);
f7 – TTL-periods (average value);
f8 – the number of A-records in the incoming DNS-message;
f9 – the number of IP-addresses of the domain name;
f10 – the value of an average distance between the IP-addresses of the domain name;
f11 – a value of the average distance between the IP-addresses in the domain name
(concerning to A-records set);
f12 – a number of the unique IP-addresses in the domain name (concerning to
Arecords sets);
f13 – a value of average distance between the unique IP-addresses in the domain name
(concerning to A-record sets);
f14 – a number of domain names which share the same IP-address;
f15 – the sign of the usage of the infrequent DNS records types, 0 – if there is such
usage, 1 – otherwise;</p>
        <p>f16 – a value of the DNS-records entropy, which is evaluated as a discrete random
variable X using the formula: H(X) =
;
f17 – a maximum DNS-messages’ size concerning to the domain name; f18 – an
average DNS-messages’ size concerning the domain name;
f19 – usage of dynamic DNS (DDNS);
f20 – an unique query ratio;
f21 – an unique query volume;
f22 – a resource records type distribution;
f23 – a DNS-query succeed sign.
3.4</p>
      </sec>
      <sec id="sec-4-4">
        <title>DNS based Attacks Detection Procedure</title>
        <p>The DNS data exchange detection stage is performed using the anomaly detection
classifier – isolation forest [20, 21]. The aim of classifier is to assign each obtained
feature vector to malicious or benign class.</p>
        <p>Isolation forest algorithm is classic classifier without the teacher. It learns using
only existing legal data and is able to detect the anomalous behavior.</p>
        <p>Let us consider the training and testing phase of the algorithms.</p>
        <p>The training phase uses the set of constructed feature vectors and outputs the set of
anomaly scores s for each feature vector.</p>
        <p>The input data for the classification algorithm is the set for each domain name
D and for a period of time t, and the result is an anomaly score rated from 0 to 1.</p>
        <p>The output of the learning phase is the set of anomaly thresholds Ts corresponding
to each analyzed feature vector that are be applied to the new data.</p>
        <p>The testing phase dials with the obtaining of new samples, where they are to be
proceed by the algorithm in order to estimate the sample’s score s using the iforest
function, as follows:
,
(7)
where iforest – the classification function for the gathered data.</p>
        <p>If the obtained value exceeds the anomaly score (s&gt; Ts), the sample is considered
anomalous and the domain referenced will be considered as the malicious domain and
is to be blocked.
3.5</p>
      </sec>
      <sec id="sec-4-5">
        <title>Blocking of the malicious DNS traffic</title>
        <p>Domain names that are to be classified can assigned into two categories: malicious
and legitimate.</p>
        <p>As soon as these domain names are identified as malicious the security scenario for
the attack’s mitigation is to be applied in order to block the malicious queries in the
network.
4</p>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>Experiments</title>
      <p>For the purpose of technique efficiency evaluation, a number of experiments were
held. An aim of the experiments was to estimate the ability of the method to detect
malicious DNS queries. To train the system, the dataset [22] was used. It presented
the benign (users’) DNS traffic. To test the system, a set of DNS-traffic tools were
used to generate malicious traffic:
1. DNScat-P (a generator of А type queries) [23];
2. DNScapy (Scapy packets generator, using SSH tunneling, including Socks
proxy) [24];
3. TUNS (generator for CNAME records) [25];
4. PSUDP (exfiltration tool for DNS queries) [26];
5. dns2tcp (query generator of the KEY and TXT types) [27];
6. tcp-over-dns (queries generator with the support of LZMA, as well with TCP
and UDP traffic tunneling [28];</p>
      <p>7. iodine (a DNS tunneling program. It uses a TUN or TAP interface on the
endpoint) [29].</p>
      <p>For the purpose of the C&amp;C server’s imitation the set of "fake" domain names was
registered. The C&amp;C servers made it possible to simulate malicious activity (such
actions as command and control traffic transfer using DNS-tunneling, cycling of
IPmapping, domain name changing, cyclically changing of DNS A-records and
NSrecords for the same domains using round robin algorithm, etc.).</p>
      <p>In addition to implement proposed technique the framework BotGRABBER was
employed [30-33]. It is a multi-vector protection system capable to analyze network
and host activity, as well as to implement the needed security scenario of the network
reconfiguration according to the type of cyberattack performed by the intruders.</p>
      <p>Experimental studies for each type of attack were conducted within 24 hours.</p>
      <p>During each experiment, the above tools generated more than 580,000 external
DNS queries. In addition, a network activity of 1,000 users was emulated.</p>
      <p>The test result of the isolating an anomalous feature vector, presented as a point in
a Gaussian distribution, is given in fig.2.</p>
      <p>The experimental results were estimated via standard sensitivity (SN), specificity
(SP), and detection efficiency (Q) performance measures, taking into account the
quantity measures of True Positives (TP), True Negatives (TN), False Positives (FP),
False Negatives (FN):</p>
      <p>SN =TP/(TP + FN), SP =TN/(TN + FP), Q =(TP + TN)/(TP + TN + FP + FN).
(8)</p>
      <p>The experimental results, presented in table 1, showed that the effectiveness of the
malware detection is in the range from 94,57 to 99,54%, while the false positives rate
not exceeded 4,2%.</p>
      <p>Possible security scenario is to be applied in the situation of DNS tunneling attack
may be as following [34]:
1. Disallowing internal DNS servers to resolve to external addresses and do the
external resolution only through a proxy should prevent this technique.
2. In the case of captive portals, resolving external addresses only after sign-up
may work. But then again, there are also other ways for getting around the
captive portal, e.g. capturing and then assuming an already signed-up MAC
address (which requires much less preparation).
3. Blocking certain domains/IP blocks/regions is surely always possible, but
ineffective if the other end could potentially be anywhere.</p>
      <p>Figure 3 shows a timeline of the DNS traffic from the malicious activity: before
attack and after the detection and the security scenario appliance.
Sensitivity,
%</p>
      <p>Specificity,</p>
      <p>%
17. Tripathi, N., Swarnkar, M., Hubballi, N. DNS spoofing in local networks made easy. In
2017 IEEE International Conference on Advanced Networks and Telecommunications
Systems (ANTS), pp. 1-6. IEEE (2017).
18. Dooley, M., Rooney, T. DNS Security Management. John Wiley &amp; Sons (2017).
19. Chung, T., van Rijswijk-Deij, R., Choffnes, D., Levin, D., Maggs, B. M., Mislove, A.,
Wilson, C. Understanding the role of registrars in DNSSEC deployment. In Proceedings of
the 2017 Internet Measurement Conference, pp. 369-383 (2017).
20. Liu, F. T., Ting, K. M., Zhou, Z. H. Isolation forest. In 2008 Eighth IEEE International</p>
      <p>Conference on Data Mining, pp. 413-422. IEEE (2008).
21. Chandola, V., Banerjee, A., Kumar, V. Anomaly Detection: A Survey, ACM Computing</p>
      <p>Surveys, Vol. 41 (3), Article 15 (2009).
22. Canadian Institute for Cybersecurity. Botnet dataset. Available online:
https://www.unb.ca/cic/datasets/botnet.html (аccessed on March 20, 2020).
23. DNScat-P. Available online: http://tadek.pietraszek.org/projects/DNScat (аccessed on</p>
      <p>March 20, 2020).
24. DNScapy. DNS tunneling with scapy. Available online: http://code.google.com/p/dnscapy
(аccessed on March 20, 2020).
25. Nussbaum, L. TUNS. On robust covert channels inside DNS. Available online:
http://hal.inria.fr/docs/00/42/56/16/PDF/tuns-sec09-article.pdf (аccessed on March 20,
2020).
26. Born, K. Psudp: A passive approach to network-wide covert communication. Available
online: http://www.kentonborn.com/sites/default/files/psudp_born_slides_bh_2010.pdf
(аccessed on March 20, 2020).
27. dns2tcp. Available online: http://www.hsc.fr/ressources/outils/dns2tcp/index.html.en
(аccessed on March 20, 2020).
28. Analogbit. tcp-over-dns. Available online: http://analogbit.com/software/tcp-over-dn
(аccessed on March 20, 2020).
29. Andersson, B. Iodine by kryo. Available online: http://code.kryo.se/iodine (аccessed on</p>
      <p>March 20, 2020).
30. Pomorova, O., Savenko, O., Lysenko, S., Kryshchuk, A., Bobrovnikova, K. A technique
for the botnet detection based on DNS-traffic analysis. In International Conference on
Computer Networks, pp. 127-138. Springer, Cham (2015).
31. Pomorova, O., Savenko, O., Lysenko, S., Nicheporuk, A. Metamorphic Viruses Detection
Technique based on the Modified Emulators. In CEUR Workshop Proceedings 1614, pp.
375-383 (2016).
32. Lysenko, S., Savenko, O., Bobrovnikova, K., Kryshchuk, A. Self-adaptive system for the
corporate area network resilience in the presence of botnet cyberattacks. In International
Conference on Computer Networks, pp. 385-401. Springer, Cham (2018).
33. Lysenko, S., Bobrovnikova, K., Savenko, O., Kryshchuk, A. BotGRABBER: SVM-Based
Self-Adaptive System for the Network Resilience Against the Botnets’ Cyberattacks. In
International Conference on Computer Networks, pp. 127-143. Springer, Cham (2019).
34. Hamann, D. Tunneling network traffic over DNS with Iodine and a SSH SOCKS proxy.</p>
      <p>Available online: https://davidhamann.de/2019/05/12/tunnel-traffic-over-dns-ssh (аccessed
on March 20, 2020).</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>AV-TEST Institute</surname>
          </string-name>
          . Available online: https://www.av-test.
          <source>org (аccessed on March 20</source>
          ,
          <year>2020</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>AV</surname>
          </string-name>
          <article-title>Comparatives laboratories</article-title>
          . Available online: http://www.av-comparatives.
          <source>org (аccessed on March 20</source>
          ,
          <year>2020</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <source>McAfee Labs Threat Report. December</source>
          <year>2019</year>
          .
          <article-title>Available online: Ошибка! Недопусти- мый объект гиперссылки</article-title>
          .
          <source>(аccessed on March 20</source>
          ,
          <year>2020</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4. Check Point Research.
          <source>The 2020 Cyber Security Report</source>
          . Available online: https://research.checkpoint.com/2020/the-2020
          <source>-cyber-security-report/ (аccessed on March 20</source>
          ,
          <year>2020</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <given-names>FBI. Cyber</given-names>
            <surname>Crime</surname>
          </string-name>
          . Available online: https://www.fbi.gov/investigate/cyber (аccessed
          <source>on March 20</source>
          ,
          <year>2020</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Trejo</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ferman</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Medina-Perez</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <given-names>Arredondo</given-names>
            <surname>Giacinti</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            ,
            <surname>Monroy</surname>
          </string-name>
          ,
          <string-name>
            <surname>R.</surname>
          </string-name>
          , RamirezMarquez, J.:
          <article-title>DNS-ADVP: A Machine Learning Anomaly Detection and Visual Platform to Protect Top-Level Domain Name Servers Against DDoS Attacks</article-title>
          .
          <source>IEEE Access</source>
          .
          <volume>7</volume>
          ,
          <fpage>116358</fpage>
          -
          <lpage>116369</lpage>
          (
          <year>2019</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>Maksutov</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Cherepanov</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Alekseev</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Detection and prevention of DNS spoofing attacks</article-title>
          .
          <source>In 2017 Siberian Symposium on Data Science and Engineering (SSDSE)</source>
          , Novosibirsk, pp.
          <fpage>84</fpage>
          -
          <lpage>87</lpage>
          (
          <year>2017</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Jin</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kakoi</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tomoishi</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yamai</surname>
            ,
            <given-names>N.</given-names>
          </string-name>
          <article-title>Efficient detection of suspicious DNS traffic by resolver separation per application program</article-title>
          .
          <source>In 2017 International Conference on Information and Communication Technology Convergence (ICTC)</source>
          , pp.
          <fpage>87</fpage>
          -
          <lpage>92</lpage>
          . IEEE (
          <year>2017</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <surname>Alieyan</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Anbar</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Almomani</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Abdullah</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Alauthman</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <article-title>Botnets Detecting Attack Based on DNS Features</article-title>
          .
          <source>In 2018 International Arab Conference on Information Technology (ACIT)</source>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>4</lpage>
          . IEEE (
          <year>2018</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>Jin</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tomoishi</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yamai</surname>
            ,
            <given-names>N.</given-names>
          </string-name>
          <article-title>Anomaly Detection by Monitoring Unintended DNS Traffic on Wireless Network</article-title>
          .
          <source>In 2019 IEEE Pacific Rim Conference on Communications, Computers and Signal Processing (PACRIM)</source>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>6</lpage>
          . IEEE (
          <year>2019</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Özdinçer</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mantar</surname>
            ,
            <given-names>H. A.</given-names>
          </string-name>
          <article-title>SDN-based Detection and Mitigation System for DNS Amplification Attacks</article-title>
          .
          <source>In 2019 3rd International Symposium on Multidisciplinary Studies and Innovative Technologies (ISMSIT)</source>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>7</lpage>
          . IEEE (
          <year>2019</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12. von Sperling, T. L.,
          <string-name>
            <surname>de Caldas Filho</surname>
            ,
            <given-names>F. L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>de</surname>
            <given-names>Sousa</given-names>
          </string-name>
          , R. T., e
          <string-name>
            <surname>Martins</surname>
            ,
            <given-names>L. M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rocha</surname>
            ,
            <given-names>R. L.</given-names>
          </string-name>
          <article-title>Tracking intruders in IoT networks by means of DNS traffic analysis</article-title>
          .
          <source>In 2017 Workshop on Communication Networks and Power Systems (WCNPS)</source>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>4</lpage>
          . IEEE (
          <year>2017</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <surname>Torabi</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Boukhtouta</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Assi</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Debbabi</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <article-title>Detecting Internet abuse by analyzing passive DNS traffic: A survey of implemented systems</article-title>
          .
          <source>IEEE Communications Surveys &amp; Tutorials</source>
          ,
          <volume>20</volume>
          (
          <issue>4</issue>
          ),
          <fpage>3389</fpage>
          -
          <lpage>3415</lpage>
          (
          <year>2018</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14.
          <string-name>
            <surname>Trevisan</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Drago</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mellia</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Munafo</surname>
            ,
            <given-names>M. M.</given-names>
          </string-name>
          <article-title>Automatic detection of DNS manipulations</article-title>
          .
          <source>In 2017 IEEE International Conference on Big Data (Big Data)</source>
          , pp.
          <fpage>4010</fpage>
          -
          <lpage>4015</lpage>
          . IEEE (
          <year>2017</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15.
          <string-name>
            <surname>Steadman</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Scott-Hayward</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          <article-title>DNSxD: Detecting Data Exfiltration Over DNS</article-title>
          .
          <source>In 2018 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)</source>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>6</lpage>
          . IEEE (
          <year>2018</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16.
          <string-name>
            <surname>Das</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Shen</surname>
            ,
            <given-names>M. Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Shashanka</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Wang</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          <article-title>Detection of Exfiltration and Tunneling over DNS</article-title>
          .
          <source>In 2017 16th IEEE International Conference on Machine Learning and Applications (ICMLA)</source>
          , pp.
          <fpage>737</fpage>
          -
          <lpage>742</lpage>
          . IEEE (
          <year>2017</year>
          ).
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>