通信学报 ›› 2021, Vol. 42 ›› Issue (5): 164-178.doi: 10.11959/j.issn.1000-436x.2021090

• 综述 • 上一篇    下一篇

DNS隐蔽信道综述

刁嘉文1, 方滨兴1,2, 崔翔2, 王忠儒3, 甘蕊灵1, 冯林2, 姜海4   

  1. 1 北京邮电大学可信分布式计算与服务教育部重点实验室,北京 100876
    2 广州大学网络空间先进技术研究院,广东 广州 510006
    3 中国网络空间研究院信息化研究所,北京 100010
    4 北京丁牛科技有限公司,北京 100081
  • 修回日期:2021-03-24 出版日期:2021-05-25 发布日期:2021-05-01
  • 作者简介:刁嘉文(1995- ),女,黑龙江林口人,北京邮电大学博士生,主要研究方向为网络安全
    方滨兴(1960- ),男,江西万年人,博士,中国工程院院士,主要研究方向为计算机体系结构、计算机网络、信息安全
    崔翔(1978- ),男,黑龙江讷河人,博士,广州大学教授,主要研究方向为网络安全
    王忠儒(1986- ),男,山东烟台人,博士,中国网络空间研究院高级工程师,主要研究方向为人工智能、网络安全
    甘蕊灵(1996- ),女,广西贵港人,北京邮电大学硕士生,主要研究方向为网络安全
    冯林(1995- ),男,重庆巫溪人,广州大学硕士生,主要研究方向为网络安全
    姜海(1976- ),男,陕西富平人,北京丁牛科技有限公司工程师,主要研究方向为网络安全、大数据、云计算
  • 基金资助:
    广东省重点研发计划基金资助项目(2019B010136003);广东省重点研发计划基金资助项目(2019B010137004);国家重点研发计划基金资助项目(2018YFB0803504);国家重点研发计划基金资助项目(2019YFA0706404)

Survey of DNS covert channel

Jiawen DIAO1, Binxing FANG1,2, Xiang CUI2, Zhongru WANG3, Ruiling GAN1, Lin FENG2, Hai JIANG4   

  1. 1 Key Laboratory of Trustworthy Distributed Computing and Service (Beijing University of Posts and Telecommunications), Ministry of Education, Beijing 100876, China
    2 Cyberspace Institute Advanced Technology, Guangzhou University, Guangzhou 510006, China
    3 Chinese Academy of Cyberspace Studies, Institute of Information Technology, Beijing 100010, China
    4 Beijing DigApis Technology Co., Ltd., Beijing 100081, China
  • Revised:2021-03-24 Online:2021-05-25 Published:2021-05-01
  • Supported by:
    The Key Research and Development Program of Guangdong Province(2019B010136003);The Key Research and Development Program of Guangdong Province(2019B010137004);The National Key Research and Development Program of China(2018YFB0803504);The National Key Research and Development Program of China(2019YFA0706404)

摘要:

DNS隐蔽信道是网络安全中不容忽视的重要安全问题。利用DNS访问服务器的操作广泛存在于传统PC、智能手机及新型基础设施的联网通信中,防火墙等基础防御设施一般不会对 DNS 数据进行过多过滤。泛在性、隐蔽性使其成为攻击者手中较理想的秘密信道,因此关注已有研究成果及发展趋势都十分必要。首先,将 DNS隐蔽信道的发展历程概括为3个发展阶段,并分析各个阶段的情况。然后,对其进行形式化定义,深入剖析构建机理,并对其存在的不可绕过的异常点进行分析归纳,总结检测方法并将其分为传统检测方式、人工智能赋能的检测方式,提出现存问题。最后,总结当前DNS隐蔽信道的主要研究方向,并对其未来的发展趋势进行展望。

关键词: DNS隐蔽信道, 命令控制, 数据泄露, 检测, 高级持续性威胁

Abstract:

DNS covert channel is an important security issue that cannot be ignored in network security.The operation of using DNS to access the server is widely used in the network communication of traditional PC, smart phones and new infrastructure.Basic defense facilities such as firewalls generally do not filter DNS data too much.The ubiquity and concealment make it an ideal secret channel for attackers.It is necessary to pay attention to the existing research results and development trends.The development process was summarized into three stages, and the situation of each stage was analyzed.Formally it was defined and the construction mechanism was deeply analyzed.The existing abnormal points that cannot be bypassed were analyzed and summarized, the detection methods were summarized and divided into traditional detection methods and artificial intelligence-powered detection methods, the existing problems were raised.Based on the above classification, the construction and detection frontiers of DNS covert channel was reviewed, and an in-depth analysis was conducted from different perspectives such as development trends, technical mechanisms, and detection methods.Finally, the main research direction of the current was summarized, and its future development trend was prospected.

Key words: DNS covert channel, C&C, data exfiltration, detection, APT

中图分类号: 

No Suggested Reading articles found!