Data · dataset · 2026
Enhancing DNS data exfiltration protection through SDN data plane programming
Listed in ZivaHub and Deakin Research Online and DMU Figshare and UCL Research Data Repository — shown once because both records carry DOI 10.17034/32632041.v1
Data exfiltration has been a lucrative goal for malicious actors for many years, leading to a cycle of detection and avoidance that has driven the evolution of data exfiltration attacks.
Description
According to a 2019 Radware report, protecting private data was the highest area of investment for cyber security. This should come as no surprise due to the impact that data breaches can have at a private and corporate level, with large-scale data breaches being reported annually [1].
The Domain Name System (DNS) protocol has been a popular choice for malicious communication channels for many years; the vulnerability was first publicly discussed in 1998. Now, many years on, this vulnerability remains and exploits against it have grown more sophisticated and varied. The essential nature of the DNS protocol for Internet communication makes handling the threat difficult.
Read the rest (4 more)
Additionally, the movement to encrypt DNS renews old vulnerabilities that could be handled with proper traffic monitoring. In this thesis, the advantages of software-defined networking (SDN) and data plane programming are identified and leveraged to detect DNS-based data exfiltration attacks, including DNS-over-HTTPS. A DNS traffic analysis tool has been created for the SDN controller utilising its logically centralised network position.
The controller application performs per-domain DNS and per-flow DoH traffic analysis for hosts throughout the network. To aid this analysis DNS-based data exfiltration attacks have been separated into 3 sub-categories: data exfiltration, protocol tunnelling, and command and control. To reduce the strain on the SDN controller, coarse-grained packet filtering is applied in the data plane to provide a rapid association for DNS packets into benign, malicious, and suspicious labels.
This labelling informs the data plane on how to treat the traffic, either forwarding, dropping, or mirroring packets, as appropriate. The SDN controller application then populates a domain blacklist held at either the internal DNS server, to allow for dynamic domain blacklisting of DNS traffic that keeps the DNS service available for the affected host, or in the data plane to block DoH traffic from an infected host. Additionally, a solution for extracting DNS-over-HTTPS from other HTTPS traffic in the data plane is presented.
The data plane traffic categorisation greatly reduces the volume of DNS and HTTPS traffic sent to the monitoring application at the SDN controller.The evaluation demonstrates that the solution’s tiered approach provides the combined benefit of reducing data loss during an attack and limiting the strain on network resources through efficient data plane programming.<br><br>
Links
Where it is published
- DOI doi.org/10.17034/32632041.v1 ↗
DOI / persistent id · from zivahub uct ac za
Catalogue records · 1
- OAI-PMH record api.figshare.com/v2/oai?verb=GetRecord&metadataPrefix=oai_dc&identifier=oai%3Af… ↗
metadata API · from zivahub uct ac za
Topics
Provenance · 4 source records, 12 field assertions
| Source | Key | Last seen | Raw |
|---|---|---|---|
| ZivaHub | oai:figshare.com:article/32632041 | 5 d ago | JSON v1 |
| Deakin Research Online | oai:figshare.com:article/32632041 | 5 d ago | JSON v1 |
| DMU Figshare | oai:figshare.com:article/32632041 | 5 d ago | JSON v1 |
| UCL Research Data Repository | oai:figshare.com:article/32632041 | 5 d ago | JSON v1 |
| Field | Assertion | Extractor | Evidence |
|---|---|---|---|
| concepts[field].anzsrc:field:460407 | mapping · rdr ucl ac uk | vocabulary-mapper@1.0.0 | keywords['network security'] |
| concepts[field].anzsrc:field:460407 | mapping · zivahub uct ac za | vocabulary-mapper@1.0.0 | keywords['network security'] |
| concepts[field].anzsrc:field:460407 | mapping · figshare dmu ac uk | vocabulary-mapper@1.0.0 | keywords['network security'] |
| concepts[field].anzsrc:field:460407 | mapping · dro deakin edu au | vocabulary-mapper@1.0.0 | keywords['network security'] |
| concepts[field].local:field:earth-environmental | mapping · dro deakin edu au | connector:dro_deakin_edu_au@1.0.0 | |
| concepts[field].local:field:earth-environmental | mapping · zivahub uct ac za | connector:zivahub_uct_ac_za@1.0.0 | |
| concepts[field].local:field:earth-environmental | mapping · figshare dmu ac uk | connector:figshare_dmu_ac_uk@1.0.0 | |
| concepts[field].local:field:earth-environmental | mapping · rdr ucl ac uk | connector:rdr_ucl_ac_uk@1.0.0 | |
| description | source · zivahub uct ac za | connector:zivahub_uct_ac_za@1.0.0 | /metadata/dc/description |
| license_text | source · zivahub uct ac za | connector:zivahub_uct_ac_za@1.0.0 | |
| publication_date | source · zivahub uct ac za | connector:zivahub_uct_ac_za@1.0.0 | |
| title | source · zivahub uct ac za | connector:zivahub_uct_ac_za@1.0.0 | /metadata/dc/title |