Showing cs.CRShow all
2 papers · 1 filter
cs.CR2025
Improving the Identification of Real-world Malware's DNS Covert Channels Using Locality Sensitive Hashing
Pascal Ruffing, Denis Petrov, Sebastian Zillien +1
Nowadays, malware increasingly uses DNS-based covert channels in order to evade detection and maintain stealthy communication with its command-and-control servers. While prior work…
cs.CR2025
Domainator: Detecting and Identifying DNS-Tunneling Malware Using Metadata Sequences
Denis Petrov, Pascal Ruffing, Sebastian Zillien +1
In recent years, malware with tunneling (or: covert channel) capabilities is on the rise. While malware research led to several methods and innovations, the detection and different…