BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: DoH Deception: Evading ML-Based Tunnel Detection wit
 h\n   Black-Box Attack Techniques\n   When: Saturday\, Aug 10\, 10:00 - 10
 :50 PDT\n   Where: LVCC West/Floor 2/W204-W207/W204-W207-Infinity - [1]Map
 \n\n   Description:\n\n   This presentation is part of a graduate research
  project that delves\n   into the vulnerabilities of Machine Learning (ML)
  models specifically\n   designed to detect DNS Over HTTPS (DoH) tunnels. 
 Previous research has\n   primarily focused on developing models that prio
 ritize accuracy and\n   explainability. However\, these studies have often
  overlooked the\n   potential of adversarial attacks\, leaving the models 
 vulnerable to\n   common adversarial attacks like black-box attacks. This 
 presentation\n   will demonstrate that all cutting-edge DoH tunnel detecti
 on models are\n   vulnerable to black-box attacks. Our approach leverages 
 real-world\n   input data generated by DoH tunnel tools\, which are constr
 ained in the\n   attack algorithm.\n\n   Moreover\, we will show specific 
 vulnerable features that model\n   developers should avoid. When this feat
 ure type is considered\, we\n   successfully evaded all DoH tunnel detecti
 on models without using\n   advanced techniques.\n\n   Notably\, the audie
 nce can use the same methods to evade most Machine\n   Learning-Based Netw
 ork Intrusion Detection Systems\, underlining our\n   findings' immediate 
 and practical implications.\n\n   ght Scholarship at the University of Ari
 zona and the University of\n   Florida\, focusing on malware analysis. Add
 itionally\, Emanuel actively\n   contributes to the OWASP Top 10 for LLM A
 pps. Committed to advancing\n   cybersecurity technology\, he shares his e
 xpertise through speaking\n   engagements and research collaborations.\n\n
    This presentation will dive into attacking ML DoH tunnel detection\n   
 models using adversarial attack techniques for evasion. The key\n   discus
 sion points are as follows:\n\n   1 DNS tunnels In this section\, we will 
 discuss the evolution of DNS.\n   We will explain why DNS over HTTPS (DoH)
  was conceived\, what\n   motivations drove it\, and why vulnerabilities f
 rom its predecessor\n   tried to mitigate them. Next\, we will demonstrate
  how attackers can\n   leverage DNS and DoH to create tunnels\, which are 
 covert channels for\n   communication that bypass traditional network secu
 rity measures. These\n   tunnels can be used to exfiltrate information or 
 as C&C (Command and\n   Control) communication channels for malicious acti
 vities.\n   Additionally\, we will highlight the most popular tools for cr
 eating\n   these tunnels using DoH.\n\n   2 DoH Tunnel Detection Models Th
 is section will discuss the primary\n   datasets the scientific community 
 uses to create ML models for\n   detecting DoH tunnels. We will highlight 
 how to extract features from\n   DoH requests and which are the most used.
  We will also address the\n   gaps and bad practices in these datasets tha
 t lead to developing\n   vulnerable models. Additionally\, we will show th
 e best practices for\n   building DoH tunnel detection models\, such as ch
 oosing the best\n   algorithms\, implementing robust feature engineering t
 echniques\, and\n   selecting the most relevant features for the model.\n\
 n   3 Adversarial Attacks This section will introduce adversarial attacks\
 ,\n   a type of attack that aims to deceive or mislead a machine learning\
 n   model by providing it with maliciously crafted input data. We will\n  
  explain how 'white' and 'black' attacks on ML models are executed and\n  
  how they differ. Furthermore\, we will explain how to adapt 'black-box\n 
   attacks\, a type of adversarial attack where the attacker does not know\
 n   the internal workings of the model\, to target DoH tunnel detection\n 
   models and similar models.\n\n   4 Attacking (DEMOs) This section will p
 resent demos covering the\n   following scenarios: First\, we will demonst
 rate how basic black-box\n   attacks work for attacking DoH tunnel detecti
 on models. Next\, we will\n   show a demo using previous attacks\, but thi
 s time\, we will incorporate\n   real-world inputs from DoH tunnel detecti
 on tools\, constraining the\n   attack algorithm. We will also identify vu
 lnerable features within the\n   dataset that attackers can exploit to byp
 ass the DoH tunnel detection\n   models. Additionally\, we will release a 
 patched open-source tool\,\n   dnstt\, to consider all considered scenario
 s. Note: The demonstrations\n   will be conducted live\, but we will have 
 pre-recorded videos to ensure\n   continuity in case of any issues.\n\n   
 5 Defending This section will explain how to defend against the\n   attack
 s presented earlier and demonstrate 'good practices and\n   techniques' fo
 r protecting against them. We will also show how to\n   build a robust mod
 el trained with adversarial attack samples generated\n   from previous att
 acks\, which can help improve the model's resilience\n   to future attacks
 .\n\n   6 Next Steps In the final section\, we will outline the future ste
 ps in\n   our research and discuss the remaining gaps. We warmly invite ne
 w\n   contributors to join our research efforts\, as your insights and\n  
  expertise can significantly advance our understanding in this field.\n   
 Links:\n\n   Experiments (Attacking DoH tunnel detection models): [2]link\
 n\n   Black Box Attack: Zero Order Optimization Attack\, constrained to\n 
   support real doh tunnel tools inputs: [3]link\n\n   Dnstt patch (ongoing
 ): You can now run it separately (dnstt + patch).\n   The provided code do
 es exactly that: [4]link\n\n   SpeakerBio:  Emanuel Valente\n   No BIO ava
 ilable\n   '\n\n   1. #LVCCW_Level2_West\n   2. https://drive.google.com/d
 rive/folders/1XJnemvBNs9wAW1LHWfT2ZVZnzbSyqx-z?usp=sharing\n   3. https://
 drive.google.com/drive/folders/1_1tK9YfqtUVxSaVjsQHMpKhFrgmX_eAT?usp=shari
 ng\n   4. https://drive.google.com/drive/folders/1qkhwAXBCy0wWasGH4RsTs06W
 cJqiTehE?usp=sharing\n\n\n
DTEND:20240810T175000Z
DTSTART:20240810T170000Z
LOCATION:RTV - LVCC West/Floor 2/W204-W207/W204-W207-Infinity
SUMMARY:DoH Deception: Evading ML-Based Tunnel Detection with Black-Box Att
 ack Techniques
END:VEVENT
END:VCALENDAR
