Analysis of Plaintext Features in DoH Traffic for DGA Domains Detection
摘要
The deployment of DNS over HTTPS (DoH) has undeniably fortified the security and confidentiality of DNS communications. However, this advancement has also opened new avenues for malicious actors who exploit the encryption mechanisms provided by DoH. The challenge of detecting DoH tunnels has been a focal point of extensive research. Nevertheless, the integration of a Domain Generation Algorithm (DGA) within a fully encrypted environment persists as a crucial investigative challenge. This article addresses one of the enduring security issues, namely, the utilization of DGA algorithms within DoH traffic. Our approach involves scrutinizing the plaintext information present in DoH traffic and evaluating its relevance in identifying DGA domains. The crux of this study lies in the establishment of a three-level classification architecture. In this regard, our models distinguish, firstly, between DoH and Non-DoH traffic; secondly, between DoH tunnel and Non-Tunnel traffic; and thirdly, between DGA and Non-DGA traffic. To this end, we have devised and made available a dataset named KDGA-Insight23, based on intrinsic statistical features of DoH. Through comprehensive experimentation utilizing various machine learning algorithms on our dataset, the demonstrated efficacy of our detection system is evident.