Health Care DNS Tunnelling Detection Method via Spiking Neural Network
摘要
A common DNS exploit that has been used for several decades to steal data is DNS tunneling. To avoid being detected as an intrusion from healthcare domain, the stolen health information is encoded and contained within DNS requests. Machine learning techniques for detection frequently make use of characteristics like DNS activity and healthcare network activity. The majority of features, such as time–frequency-related information, can only be obtained when data exfiltration occurs. Identifying a malicious query from a single DNS suggestion is key to preventing data exfiltration based on DNS tunneling. We can perceive DNS tunnelling before healthcare data exfiltration by not using internet traffic properties or DNS behavior information. In this paper, we describe a detection method based on deep learning that uses DNS query payloads as predictive variables in the models. Using the Spiking Neural network (SNN) in healthcare DNS Tunnelling Detection Method a DNS Tunnelling attack or not? Specificity, sensitivity, f1 score, accuracy, and Matthew's correlation coefficient (MCC) are the factors taken into account when evaluating the efficiency of the suggested model. In comparison to the Proposed Spiking neural network, the Existing Deep Neural Network (DNN), Mobile Net, and Recurrent Neural Network (RNN) technique improves the performance of a DNS tunneling detection method in a real-world network system. Results indicate that the suggested strategy is far more dependable than existing methods and achieves a 99.84% accuracy rate.