DNS Data Exfiltration Detection Using Online Planning for POMDP
Yakov Bubnov
European Journal of Engineering and Technology Research, 2019, vol. 4, issue 9, 22-25
Abstract:
This paper addresses a problem of blocking Domain Name System (DNS) exfiltration in a computer network. DNS exfiltration implies unauthorized transfer of sensitive data from the organization network to the remote adversary. Given detector of data exfiltration in DNS lookup queries this paper proposes an approach to automate query blocking decisions. More precisely, it defines an L-parametric Partially Observable Markov Decision Process (POMDP) formulation to enforce query blocking strategy on each network egress point, where L is a hyper-parameter that defines necessary level of the network security. The efficiency of the approach is based on (i) absence of interactions between distributed detectors, blocking decisions are taken individually by each detector; (ii) blocking strategy is applied to each particular query, therefore minimizing potentially incorrect blocking decisions.
Keywords: Data Exfiltration; Domain Name System; POMDP; Tunneling Detection (search for similar items in EconPapers)
Date: 2019
References: View complete reference list from CitEc
Citations:
Downloads: (external link)
https://eu-opensci.org/index.php/ejeng/article/view/61500 Abstract page (text/html)
https://eu-opensci.org/index.php/ejeng/article/download/61500/12219 Full text (application/pdf)
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:epw:ejeng0:v:4:y:2019:i:9:id:61500
DOI: 10.24018/ejeng.2019.4.9.1500
Access Statistics for this article
More articles in European Journal of Engineering and Technology Research from European Open Science
Bibliographic data for series maintained by Support ().