• Journal of Internet Computing and Services
    ISSN 2287 - 1136 (Online) / ISSN 1598 - 0170 (Print)
    https://jics.or.kr/

Research on DNS DRDoS Detection Methods Using CNN


Hoon Shin, Jaeyeong Jeong, Kyu-min Cho, Jae-il Lee, Dong-kyoo Shin, Journal of Internet Computing and Services, Vol. 25, No. 6, pp. 131-145, Dec. 2024
10.7472/jksii.2024.25.6.131, Full Text:
Keywords: AI Security, Artificial intelligence, Machine Learning, Deep Learning, CNN, DDoS, DrDoS, image processing, Image Classification

Abstract

Domain Name System (DNS) amplification Distributed Reflection Denial of Service (DRDoS) is a type of Distributed Denial of Service (DDoS) attack in which multiple hosts spoof the source IP to that of the target system and send requests to DNS servers. As a result, the response packets flood the target system. The attacker conceals the origin of the attack, making it difficult to identify the attacker or detect abnormal packets. Additionally, legitimate DNS servers are often used as attack agents. Since User Datagram Protocol (UDP) is used in these attacks, it is challenging to detect anomalies based on session protocols, as is done in Transmissoon Control Protocol (TCP)-based DDoS attacks. In this paper, we propose a method for detecting DNS amplification DRDoS attacks by converting attack packets into images and training a Convolutional Neural Network (CNN) to recognize these attacks. Although this method may have a lower detection rate compared to approaches that extract and learn specific DDoS characteristics from packets, it offers the advantage of faster detection due to the omission of the data preprocessing step. Given the nature of DDoS attacks, where real-time response is often more critical than achieving near-perfect detection accuracy, this faster detection capability can be particularly valuable in practical scenarios.


Statistics
Show / Hide Statistics

Statistics (Cumulative Counts from November 1st, 2017)
Multiple requests among the same browser session are counted as one view.
If you mouse over a chart, the values of data points will be shown.


Cite this article
[APA Style]
Shin, H., Jeong, J., Cho, K., Lee, J., & Shin, D. (2024). Research on DNS DRDoS Detection Methods Using CNN. Journal of Internet Computing and Services, 25(6), 131-145. DOI: 10.7472/jksii.2024.25.6.131.

[IEEE Style]
H. Shin, J. Jeong, K. Cho, J. Lee, D. Shin, "Research on DNS DRDoS Detection Methods Using CNN," Journal of Internet Computing and Services, vol. 25, no. 6, pp. 131-145, 2024. DOI: 10.7472/jksii.2024.25.6.131.

[ACM Style]
Hoon Shin, Jaeyeong Jeong, Kyu-min Cho, Jae-il Lee, and Dong-kyoo Shin. 2024. Research on DNS DRDoS Detection Methods Using CNN. Journal of Internet Computing and Services, 25, 6, (2024), 131-145. DOI: 10.7472/jksii.2024.25.6.131.