Data is a critical feature of the data-driven technological world. During the Covid pandemic, most of the organizations shifted to the cloud network for data transfer and storage. As more organizations and individuals shift to the cloud platforms, exfiltration of the data in the cloud network has become a serious threat. DNS-based data exfiltration is a commonly used technique by attackers for accessing confidential data in cloud platforms using DNS query packets. Different methodologies especially machine learning models were proposed for the detection of exfiltration attacks in on-premises networks. In a cloud environment, security, availability, scalability, and most importantly reliability of the detection technique are the important performance metric. In this work, a cloud machine learning model which is a hybrid of CNN and LSTM with an additional mechanism of attention applied to them is proposed. By applying the attention technique to the outputs of the CNN and LSTM, the features critical in detecting exfiltration are highlighted thereby increasing the accuracy of the model and reducing the number of false positive predictions. This model provided higher accuracy, security, and reliability in DNS exfiltration detection in cloud platforms compared to the existing models.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

CLAM – CNN and LSTM with Attention Mechanism for DNS Data Exfiltration Detection

  • Jisha Joy,
  • Shivani Jaswal

摘要

Data is a critical feature of the data-driven technological world. During the Covid pandemic, most of the organizations shifted to the cloud network for data transfer and storage. As more organizations and individuals shift to the cloud platforms, exfiltration of the data in the cloud network has become a serious threat. DNS-based data exfiltration is a commonly used technique by attackers for accessing confidential data in cloud platforms using DNS query packets. Different methodologies especially machine learning models were proposed for the detection of exfiltration attacks in on-premises networks. In a cloud environment, security, availability, scalability, and most importantly reliability of the detection technique are the important performance metric. In this work, a cloud machine learning model which is a hybrid of CNN and LSTM with an additional mechanism of attention applied to them is proposed. By applying the attention technique to the outputs of the CNN and LSTM, the features critical in detecting exfiltration are highlighted thereby increasing the accuracy of the model and reducing the number of false positive predictions. This model provided higher accuracy, security, and reliability in DNS exfiltration detection in cloud platforms compared to the existing models.