Deteksi Tunneling Domain Name System dengan Fitur Cache Property

Zalfa Hilmi Abdilah(1), Atep Aulia Rahman(2*),

(1) Universitas Widyatama, Bandung, Jawa Barat, Indonesia
(2) Universitas Widyatama, Bandung, Jawa Barat, Indonesia
(*) Corresponding Author


Many companies and agencies are being attacked with data exfiltration. The attack was carried out through malware from the target by exploiting secret channels and abusing the domain system. (DNS). By creating a virus by an attacker that can infect the target malware, it will generate a client tunelling, so that the attacker can enter through the communication channels he has created to the target Malware. Attackers can control malware remotely and steal data that leaks data from targets, which will affect the profitability of companies and agencies. Therefore, the author prioritizes the traces left behind of DNS tuneling that cannot be hidden by proposing the property cache feature as a method of detecting DNS tuning

JURASIK (Jurnal Riset Sistem Informasi dan Teknik Informatika)
