Show simple item record

dc.contributor.authorKhodjaeva, Yulduz
dc.date.accessioned2021-12-17T19:39:26Z
dc.date.available2021-12-17T19:39:26Z
dc.date.issued2021-12-17T19:39:26Z
dc.identifier.urihttp://hdl.handle.net/10222/81120
dc.description.abstractThe thesis proposes the concept of "entropy of a flow" to augment flow statistical features for DNS tunnelling detection, specifically DNS over HTTPS traffic. To achieve this, the use of flow exporters, namely Argus, DoHlyzer and Tranalyzer2 are explored. Flow features are then augmented with the flow entropy, calculated in three different ways: entropy over all packets of a flow, entropy over the first 96 bytes of a flow, entropy over the first n-packets of a flow. These features are provided as input to five machine learning classifiers, specifically Decision Tree, Random Forest, Logistic Regression, Support Vector Machine and Naive Bayes to detect malicious behaviours in different publicly available datasets. Evaluations show that the Decision Tree algorithm could reach an F-measure of approximately 99.7% when flow statistical features are augmented with the flow entropy of the first four packets. This model is then optimized using TPOT-AutoML, where the Random Forest classifier provided the best pipeline configuration for the same features.en_US
dc.language.isoenen_US
dc.subjectflow entropyen_US
dc.subjectDNS tunnellingen_US
dc.subjectMachine Learningen_US
dc.subjectAutoMLen_US
dc.subjectDNS over HTTPSen_US
dc.titleDetecting malicious DNS tunnels via network flow entropyen_US
dc.date.defence2021-12-16
dc.contributor.departmentFaculty of Computer Scienceen_US
dc.contributor.degreeMaster of Computer Scienceen_US
dc.contributor.external-examinern/aen_US
dc.contributor.graduate-coordinatorMichael McAllisteren_US
dc.contributor.thesis-readerSrinivas Sampallien_US
dc.contributor.thesis-readerRiyad Alshammarien_US
dc.contributor.thesis-supervisorNur Zincir-Heywooden_US
dc.contributor.ethics-approvalNot Applicableen_US
dc.contributor.manuscriptsNot Applicableen_US
dc.contributor.copyright-releaseNot Applicableen_US
 Find Full text

Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record