DNS Tunneling Queries for Binary Classification

Published: 4 October 2021| Version 2 | DOI: 10.17632/mzn9hvdcxg.2
Contributor:
Yakov Bubnov

Description

Binary dataset provides labeled domain names divided into two categories: 0 - regular domain names, 1 - domain names with tunnels. Multilabel dataset provides domain names divided into five categories: 0 - regular domain names, 1 - dns2tcp, 2 - dnscapy, 3 - iodine, 4 - tuns.

Files

Steps to reproduce

These DNS names are collected through passing a 2MiB file through SSH connection established over DNS tunnel. Regular DNS names where retrieved from OpenDNS respository, Google hosted domains and domains of Content Delivery Networks. The file was created using random generator that uniformly produces letters from English alphabet. The following tools where used to establish DNS tunnels: dns2tcp, dnscapy, iodine, tuns.

Institutions

Belorusskij gosudarstvennyi universitet informatiki i radioelektroniki

Categories

Networking

Licence