Affiliation:
1. State Key Laboratory of Mathematical Engineering and Advanced Computing, Zhengzhou 450000, China
Abstract
Tunnels, a key technology of traffic obfuscation, are increasingly being used to evade censorship. While providing convenience to users, tunnel technology poses a hidden danger to cybersecurity due to its concealment and camouflage capabilities. In contrast to previous studies of encrypted traffic detection, we perform the first measurement study of tunnel traffic and its unique characteristics and focus on the challenges and solutions in detecting tunnel traffic among traditional and machine learning techniques. This study covers an almost twenty-year research period from 2003 to 2022. First, we present the concepts of two types of tunnels, broad and narrow tunnels, respectively, as well as a framework for major tunnel applications, such as Tor (the second-generation onion router), proxy, VPN, and their relationships. Second, we analyze state-of-the-art methods from traditional to machine learning applications to systematize tunnel traffic detection, including HTTP, HTTPS, DNS, SSH, TCP, ICMP and IPSec. A quantitative evaluation is presented with five crucial indicators applied to the detection methods and reviews. We further discuss the research work based on datasets, feature engineering, and challenges that have are solved, partly solved and unsolved. Finally, by providing open questions and the potential directions, we hope to inspire future work in this area.
Funder
National Key R&D Program of China
Subject
Fluid Flow and Transfer Processes,Computer Science Applications,Process Chemistry and Technology,General Engineering,Instrumentation,General Materials Science
Reference79 articles.
1. (2022, October 01). Available online: https://www.cert.org.cn/publish/main/upload/File/CNCERTreport202112.pdf.
2. Identifying Fast-Flux Botnet With AGD Names at the Upper DNS Hierarchy;Zang;IEEE Access,2018
3. (2022, October 01). Available online: https://www.secrss.com/articles/40646.
4. Do, V.T., Engelstad, P.E., Feng, B., and Do, T.V. (2017, January 20–23). Detection of DNS Tunneling in Mobile Networks Using Machine Learning. Proceedings of the International Conference on Information Science and Applications, Macau, China.
5. Machine Learning Based Classification Accuracy of Encrypted Service Channels: Analysis of Various Factors;Seddigh;J. Netw. Syst. Manag.,2020
Cited by
2 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献