FINDING · DETECTION

ESPRESSO achieves only TPR 0.132 at FPR ≤ 10⁻³ in network-mode for DNS-tunneled traffic—near chance—compared to TPR 0.992 for SSH traffic at the same threshold. The paper attributes this to the polling-based communication mechanism of dnscat2, which disrupts the timing patterns that interval-based flow correlation relies on.

From 2026-mathews-tracing-chain-deepTracing the Chain: Deep Learning for Stepping-Stone Intrusion Detection · §V-B, Table III · 2026 · arXiv preprint

Implications

Tags

censors
generic
techniques
flow-correlationtraffic-shape
defenses
dns-tunneling

Extracted by claude-sonnet-4-6 — review before relying.