Unsupervised SOM-Based Intrusion Detection System for DNS Tunneling Attacks

  • Júlio F. Luz UFPE / Tempest Security Intelligence
  • Paulo Freitas de Araujo-Filho UFPE
  • Henrique F. Arcoverde UFPE / Tempest Security Intelligence
  • Divanilson R. Campelo UFPE


Although the Domain Name System (DNS) is an essential protocol for Internet operation, it may also be used for malicious activities, such as data exfiltration, through the establishment of malicious DNS tunnels. In this paper, we propose an unsupervised intrusion detection system (IDS) for detecting malicious DNS tunneling activities by leveraging self-organizing maps (SOM). Our experimental results show that our proposed solution achieved an F1-score of 0.9460, outperforming similar existing techniques in publicly available datasets, and successfully detected attacks conducted in a corporate network.


