UFU-Do53-EXF e UFU-DoH-EXF: conjuntos de dados para detecção de exfiltração via DNS

  • Cristiano L. M. Borges UFU
  • Rodrigo S. Miani UFU

Resumo


A exfiltração de dados via Domain Name System (DNS) permanece como um problema relevante em segurança cibernética, pois o DNS é um serviço essencial ao funcionamento das redes e pode ser abusado como canal para transferência não autorizada de dados. Este artigo apresenta dois conjuntos de dados complementares, UFU-Do53-EXF e UFU-DoH-EXF, concebidos para apoiar o estudo da exfiltração em DNS convencional sobre a porta 53 e DNS sobre HTTPS. A proposta combina geração controlada de tráfego benigno e malicioso, capturas de pacotes em formato PCAP, um pipeline reprodutível de processamento PCAP-to-Flow e extração de atributos específicos por protocolo. Após normalização, o conjunto UFU-Do53-EXF contém 5.351.064 amostras, enquanto o UFU-DoH-EXF contém 1.048.575 fluxos TCP/443. Em conjunto, os dados apoiam a análise do comportamento de exfiltração tanto em tráfego DNS em texto claro quanto em tráfego criptografado. Avaliações supervisionadas de referência, com classificadores amplamente utilizados na literatura, indicam que as representações propostas são consistentes e capturam padrões discriminativos para distinguir tráfego benigno de atividades de exfiltração.

Referências

Abualghanam, O., Alazzam, H., Elshqeirat, B., Qatawneh, M., and Almaiah, M. A. (2023). Real-Time Detection System for Data Exfiltration over DNS Tunneling Using Machine Learning. Electronics, 12(6).

Ahmed, J., Gharakheili, H. H., Raza, Q., Russell, C., and Sivaraman, V. (2019). Real-Time Detection of DNS Exfiltration and Tunneling from Enterprise Networks. In 2019 IFIP/IEEE Symposium on Integrated Network and Service Management (IM), pages 649–653.

Ahmed, J., Habibi Gharakheili, H., Raza, Q., Russell, C., and Sivaraman, V. (2020). Monitoring Enterprise DNS Queries for Detecting Data Exfiltration From Internal Hosts. IEEE Transactions on Network and Service Management, 17(1):265–279.

Bowes, R. (2022). dnscat2.

Elaoumari, A. (2025). Evasion-Resilient Detection of DNS-over-HTTPS Data Exfiltration: A Practical Evaluation and Toolkit. MSc Dissertation, University of Kent, School of Computing.

Garcia, S. and Valeros, V. (2023). Towards a better labeling process for network security datasets. _eprint: 2305.01337.

Güneş Gürsoy, A., Varol, A., and Nasab, A. (2024). DNS Tunnel Problem In Cybersecurity. In 2024 12th International Symposium on Digital Forensics and Security (ISDFS). IEEE.

Hoffman, P. and McManus, P. (2018). DNS Queries over HTTPS (DoH). Issue: 8484 Type: RFC Published: Internet Requests for Comments.

Le Pochat, V., Van Goethem, T., Tajalizadehkhoob, S., Korczyński, M., and Joosen, W. (2019). Tranco: A Research-Oriented Top Sites Ranking Hardened Against Manipulation. In Proceedings of the Network and Distributed System Security Symposium (NDSS).

Luz, J., Araujo-Filho, P., Arcoverde, H., and Campelo, D. (2023). Unsupervised SOM-Based Intrusion Detection System for DNS Tunneling Attacks. In Anais do XXIII Simpósio Brasileiro de Segurança da Informação e de Sistemas Computacionais, pages 516–521, Porto Alegre, RS, Brasil. SBC.

Mahdavifar, S., Salem, A., Victor, P., Razavi, A., Garzon, M., Hellberg, N., and Habibi Lashkari, A. (2021). Lightweight Hybrid Detection of Data Exfiltration using DNS based on Machine Learning. In ICCNS 2021: The 11th International Conference on Communication and Network Security, pages 80–86.

MITRE ATT&CK (2026a). T1041 – Exfiltration Over C2 Channel.

MITRE ATT&CK (2026b). T1048 – Exfiltration Over Alternative Protocol.

MITRE ATT&CK (2026c). T1048.003 – Exfiltration Over Unencrypted Non-C2 Protocol.

Moure-Garrido, M., Campo, C., and Garcia-Rubio, C. (2023). Real time detection of malicious DoH traffic using statistical analysis. Computer Networks, 234:109910.

Nadler, A., Aminov, A., and Shabtai, A. (2019). Detection of malicious and low throughput data exfiltration over the DNS protocol. Computers & Security, 80:36–53.

Ozery, Y., Nadler, A., and Shabtai, A. (2024). Information-Based Heavy Hitters for Real-Time DNS Data Exfiltration Detection. In Network and Distributed System Security Symposium (NDSS) 2024.

Palau, F., Catania, C., Guerra, J., García, S. J., and Rigaki, M. (2019). Detecting DNS Threats: A Deep Learning Model to Rule Them All. In XX Simposio Argentino de Inteligencia Artificial (ASAI 2019) - JAIIO 48, pages 90–101, Salta, Argentina. Universidad Nacional de La Plata. Backup Publisher: Sociedad Argentina de Informática e Investigación Operativa.

Rescorla, E. (2018). The Transport Layer Security (TLS) Protocol Version 1.3. Published: RFC 8446.

Rescorla, E., Oku, K., Sullivan, N., and Wood, C. A. (2026). TLS Encrypted Client Hello. RFC 9849, RFC Editor.

Sabir, B., Ullah, F., Babar, M. A., and Gaire, R. (2021). Machine Learning for Detecting Data Exfiltration: A Review. ACM Comput. Surv., 54(3). Place: New York, NY, USA.

Salat, L., Davis, M., and Khan, N. (2023). DNS Tunnelling, Exfiltration and Detection over Cloud Environments. Sensors, 23(2760).

Srivastava, G., Jhaveri, R. H., Bhattacharya, S., Pandya, S., Rajeswari, Maddikunta, P. K. R., Yenduri, G., Hall, J. G., Alazab, M., and Gadekallu, T. R. (2022). XAI for Cybersecurity: State of the Art, Challenges, Open Issues and Future Directions. _eprint: 2206.03585.

Steadman, J. and Scott-Hayward, S. (2018). DNSxD: Detecting Data Exfiltration Over DNS. In 2018 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN), pages 1–6.

Tang, R., Huang, C., Zhou, Y., Wu, H., Lu, X., Sun, Y., Li, Q., Li, J., Huang, W., Sun, S., and others (2020). A practical machine learning-based framework to detect dns covert communication in enterprises. In International Conference on Security and Privacy in Communication Systems, pages 1–21. Springer.

Zhan, M. and others (2022). Detecting DNS over HTTPS based data exfiltration. Computer Networks.
Publicado
01/09/2026
BORGES, Cristiano L. M.; MIANI, Rodrigo S.. UFU-Do53-EXF e UFU-DoH-EXF: conjuntos de dados para detecção de exfiltração via DNS. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 111-126. DOI: https://doi.org/10.5753/sbseg.2026.26992.

Artigos mais lidos do(s) mesmo(s) autor(es)