Pairing DNS queries and responses in feature extraction raises MLP and Random Forest accuracy above 83% for detecting SSH/SFTP/Telnet tunnels, with roughly 95% reduction in data size.
Title resolution pending
1 Pith paper cite this work. Polarity classification is still indexing.
1
Pith paper citing it
fields
cs.CR 1years
2019 1verdicts
UNVERDICTED 1representative citing papers
citing papers explorer
-
Identifying DNS-tunneled traffic with predictive models
Pairing DNS queries and responses in feature extraction raises MLP and Random Forest accuracy above 83% for detecting SSH/SFTP/Telnet tunnels, with roughly 95% reduction in data size.