Related Experiment Video
Updated: Aug 7, 2025

Integration of 5G Experimentation Infrastructures into a Multi-Site NFV Ecosystem
Published on: February 3, 2021
DNS Tunnelling, Exfiltration and Detection over Cloud Environments.
Lehel Salat1, Mastaneh Davis1, Nabeel Khan2
1Faculty of Engineering, Computing and the Environment, Kingston University, Penrhyn Rd., Kingston upon Thames KT1 2EE, UK.
This study demonstrates effective detection of DNS tunneling attacks in cloud environments using the open-source Elastic stack. The developed monitoring system offers a low-cost, user-friendly solution for organizations to enhance their cybersecurity posture.
Area of Science:
- Cybersecurity
- Network Protocols
- Cloud Computing Security
Background:
- The Domain Name System (DNS) is critical for internet operations but vulnerable to sophisticated attacks.
- Increased reliance on cloud services introduces new security challenges, including exploitation of DNS protocols.
- Cybercriminals increasingly leverage DNS for data exfiltration and command-and-control.
Purpose of the Study:
- To investigate the efficacy of DNS tunneling techniques (Iodine, DNScat) in cloud environments.
- To develop and evaluate a cost-effective DNS monitoring and detection system for organizations with limited cybersecurity resources.
- To enhance the detection capabilities against malicious DNS activities in cloud infrastructure.
Main Methods:
- Conducted DNS tunneling experiments using Iodine and DNScat in Google Cloud and AWS environments.
- Implemented various DNS tunneling detection techniques, including payload and traffic analysis.
- Utilized the Elastic stack, an open-source framework, for configuring the DNS monitoring system and analyzing DNS logs.
Main Results:
- Successfully achieved data exfiltration using DNS tunneling methods under diverse firewall configurations.
- Developed a cloud-based monitoring system with a reliable detection rate for malicious DNS activities.
- Demonstrated the effectiveness of the Elastic stack for real-time DNS log analysis and threat detection.
Conclusions:
- The proposed cloud-based monitoring system provides an accessible and effective solution for detecting DNS tunneling attacks.
- Organizations, particularly small ones with limited cybersecurity expertise, can benefit from this low-cost, open-source monitoring approach.
- Continuous monitoring and analysis of DNS traffic are crucial for identifying and mitigating emerging cyber threats in cloud environments.
More Related Videos
Related Concept Videos
Masking and Demasking Agents
There are many masking agents, such as cyanide, fluoride, triethanolamine, thiourea, and 2,3-bis(sulfanyl)propan-1-ol (formerly 2,3-dimercapto-1-propanol), with the masking agent chosen based on...
Issues And Trends In Healthcare Delivery System
Cost Containment
Payment for healthcare services has historically promoted adoption of costly and often unnecessary or inefficient...
Drug Excretion: Pulmonary and Glandular Routes
Drugs can also be excreted in breast milk, which is crucial for breastfeeding infants. The...
Leaky Scanning
Reabsorption and Secretion in the PCT
Transport mechanisms involving sodium ions (Na+) contribute significantly to solute reabsorption. These mechanisms include symport and antiport processes.
A key example is the...
Gas Chromatography: Types of Detectors-II

