中文
相关论文

相关论文: Detection of Malicious DNS-over-HTTPS Traffic: An …

200 篇论文

Effective applications of vehicular ad hoc networks in traffic signal control require new methods for detection of malicious data. Injection of malicious data can result in significantly decreased performance of such applications, increased…

网络与互联网体系结构 · 计算机科学 2017-04-03 Bartlomiej Placzek , Marcin Bernas

Nearly every service on the Internet relies on the Domain Name System (DNS), which translates a human-readable name to an IP address before two endpoints can communicate. Today, DNS traffic is unencrypted, leaving users vulnerable to…

网络与互联网体系结构 · 计算机科学 2020-02-25 Austin Hounsel , Kevin Borgolte , Paul Schmitt , Jordan Holland , Nick Feamster

The use of DNS over HTTPS (DoH) tunneling by an attacker to hide malicious activity within encrypted DNS traffic poses a serious threat to network security, as it allows malicious actors to bypass traditional monitoring and intrusion…

Machine-learning-based anomaly detection (ML-based AD) has been successful at detecting DDoS events in the lab. However published evaluations of ML-based AD have used only limited data and provided minimal insight into why it works. To…

网络与互联网体系结构 · 计算机科学 2020-06-23 Hang Guo , Xun Fan , Anh Cao , Geoff Outhred , John Heidemann

In this paper, we propose HyperVision, a realtime unsupervised machine learning (ML) based malicious traffic detection system. Particularly, HyperVision is able to detect unknown patterns of encrypted malicious traffic by utilizing a…

密码学与安全 · 计算机科学 2023-02-01 Chuanpu Fu , Qi Li , Ke Xu

Unencrypted DNS traffic between users and DNS resolvers can lead to privacy and security concerns. In response to these privacy risks, many browser vendors have deployed DNS-over-HTTPS (DoH) to encrypt queries between users and DNS…

密码学与安全 · 计算机科学 2025-10-31 Ranya Sharma , Nick Feamster

Nowadays, malware increasingly uses DNS-based covert channels in order to evade detection and maintain stealthy communication with its command-and-control servers. While prior work has focused on detecting such activity, identifying…

密码学与安全 · 计算机科学 2025-11-26 Pascal Ruffing , Denis Petrov , Sebastian Zillien , Steffen Wendzel

The primary objective of an anonymity tool is to protect the anonymity of its users through the implementation of strong encryption and obfuscation techniques. As a result, it becomes very difficult to monitor and identify users activities…

密码学与安全 · 计算机科学 2023-11-29 Javeriah Saleem , Rafiqul Islam , Zahidul Islam

Distributed Denial-of-Service (DDoS) attacks represent a persistent threat to modern telecommunications networks: detecting and counteracting them is still a crucial unresolved challenge for network operators. DDoS attack detection is…

网络与互联网体系结构 · 计算机科学 2021-11-05 Damu Ding , Marco Savi , Domenico Siracusa

With the rapid development of Internet of Things technologies, the next generation traffic monitoring infrastructures are connected via the web, to aid traffic data collection and intelligent traffic management. One of the most important…

人工智能 · 计算机科学 2023-04-25 Yue Hu , Yuhang Zhang , Yanbing Wang , Daniel Work

Intrusion detection systems (IDS) are used to monitor networks or systems for attack activity or policy violations. Such a system should be able to successfully identify anomalous deviations from normal traffic behavior. Here we discuss the…

密码学与安全 · 计算机科学 2022-05-17 M. Andrecut

In this paper, we focus on the development of a method that detects abnormal trajectories of road users at traffic intersections. The main difficulty with this is the fact that there are very few abnormal data and the normal ones are…

计算机视觉与模式识别 · 计算机科学 2018-09-05 Pankaj Raj Roy , Guillaume-Alexandre Bilodeau

In the authors' opinion, anomaly detection systems, or ADS, seem to be the most perspective direction in the subject of attack detection, because these systems can detect, among others, the unknown (zero-day) attacks. To detect anomalies,…

计算机视觉与模式识别 · 计算机科学 2019-03-25 Yuri Monakhov , Oleg Nikitin , Anna Kuznetsova , Alexey Kharlamov , Alexandr Amochkin

Improperly configured domain name system (DNS) servers are sometimes used as packet reflectors as part of a DoS or DDoS attack. Detecting packets created as a result of this activity is logically possible by monitoring the DNS request and…

网络与互联网体系结构 · 计算机科学 2021-11-10 Keiichi Shima , Ryo Nakamura , Kazuya Okada , Tomohiro Ishihara , Daisuke Miyamoto , Yuji Sekiya

The network security analyzers use intrusion detection systems (IDSes) to distinguish malicious traffic from benign ones. The deep learning-based IDSes are proposed to auto-extract high-level features and eliminate the time-consuming and…

密码学与安全 · 计算机科学 2023-03-07 Mahdi Soltani , Khashayar Khajavi , Mahdi Jafari Siavoshani , Amir Hossein Jahangir

It is important to be able to detect and classify malicious network traffic flows such as DDoS attacks from benign flows. Normally the task is performed by using supervised classification algorithms. In this paper we analyze the usage of…

密码学与安全 · 计算机科学 2018-08-08 Quang-Vinh Dang

In this paper, we present MORTON, a method that identifies compromised devices in enterprise networks based on the existence of routine DNS communication between devices and disreputable host names. With its compact representation of the…

密码学与安全 · 计算机科学 2021-01-22 Yael Daihes , Hen Tzaban , Asaf Nadler , Asaf Shabtai

Hypertext transfer protocol (HTTP) is one of the most widely used protocols on the Internet. As a consequence, most attacks (i.e., SQL injection, XSS) use HTTP as the transport mechanism. Therefore, it is crucial to develop an intelligent…

机器学习 · 计算机科学 2021-08-05 Mateusz Gniewkowski , Henryk Maciejewski , Tomasz R. Surmacz , Wiktor Walentynowicz

Malicious domains are one of the major resources required for adversaries to run attacks over the Internet. Due to the important role of the Domain Name System (DNS), extensive research has been conducted to identify malicious domains based…

密码学与安全 · 计算机科学 2018-12-04 Yury Zhauniarovich , Issa Khalil , Ting Yu , Marc Dacier

The Domain Name System (DNS) is a core Internet service that translates domain names into IP addresses. It is a distributed database and protocol with many known weaknesses that subject to countless attacks including spoofing attacks,…

密码学与安全 · 计算机科学 2022-11-16 Alshaima Almarzooqi , Jawahir Mahmoud , Bayena Alzaabi , Arsiema Ghebremichael , Monther Aldwairi