Research Article

DNS Tunneling Detection Method Based on Multilabel Support Vector Machine

Table 2

Sample of utilized features.

ConnectionsDNS request lengthIP request lengthIP response lengthEncoded DNS request nameRequest application layer entropyIP packet entropyQuery name entropyClass label

11341622533832ca326862beee59d6776a6fe9d7beee5745edc5.3890385.133664.02192FTP
21321601763832be74be6470fd61616261637561614167d4c4.9153864.793273.64144HTTP
31391672783832be74ee6464fd6161626163756161e746b3144.9925124.534173.54144HTTPS
457374853832ca326862beee59d6676a6fe9d3beee5741.5849631.584961.58496POP3
51301581643832ca326862beee59d6676a6fe9d3beee5745.5088195.093664.02192HTTP
61301582373832ca326862beee59d6676a6fe9cbbeee5745ed5.605425.228754.02192FTP
757261857a64611.5849631.584961.58496FTP
813015899login.wildraiderz.com5.5904955.173663.82192Normal