Domainator: Detecting and Identifying DNS-Tunneling Malware Using Metadata Sequences

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Petrov, Denis, Ruffing, Pascal, Zillien, Sebastian, Wendzel, Steffen
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915626375708672
author Petrov, Denis
Ruffing, Pascal
Zillien, Sebastian
Wendzel, Steffen
author_facet Petrov, Denis
Ruffing, Pascal
Zillien, Sebastian
Wendzel, Steffen
contents In recent years, malware with tunneling (or: covert channel) capabilities is on the rise. While malware research led to several methods and innovations, the detection and differentiation of malware solely based on its DNS tunneling features is still in its infancy. Moreover, no work so far has used the DNS tunneling traffic to gain knowledge over the current actions taken by the malware. In this paper, we present Domainator, an approach to detect and differentiate state-of-the-art malware and DNS tunneling tools without relying on trivial (but quickly altered) features such as "magic bytes" that are embedded into subdomains. Instead, we apply an analysis of sequential patterns to identify specific types of malware. We evaluate our approach with 7 different malware samples and tunneling tools and can identify the particular malware based on its DNS traffic. We further infer the rough behavior of the particular malware through its DNS tunneling artifacts. Finally, we compare our Domainator with related methods.
format Preprint
id arxiv_https___arxiv_org_abs_2505_22220
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Domainator: Detecting and Identifying DNS-Tunneling Malware Using Metadata Sequences
Petrov, Denis
Ruffing, Pascal
Zillien, Sebastian
Wendzel, Steffen
Cryptography and Security
Networking and Internet Architecture
In recent years, malware with tunneling (or: covert channel) capabilities is on the rise. While malware research led to several methods and innovations, the detection and differentiation of malware solely based on its DNS tunneling features is still in its infancy. Moreover, no work so far has used the DNS tunneling traffic to gain knowledge over the current actions taken by the malware. In this paper, we present Domainator, an approach to detect and differentiate state-of-the-art malware and DNS tunneling tools without relying on trivial (but quickly altered) features such as "magic bytes" that are embedded into subdomains. Instead, we apply an analysis of sequential patterns to identify specific types of malware. We evaluate our approach with 7 different malware samples and tunneling tools and can identify the particular malware based on its DNS traffic. We further infer the rough behavior of the particular malware through its DNS tunneling artifacts. Finally, we compare our Domainator with related methods.
title Domainator: Detecting and Identifying DNS-Tunneling Malware Using Metadata Sequences
topic Cryptography and Security
Networking and Internet Architecture
url https://arxiv.org/abs/2505.22220