FTExfil: DNS Tunneling via Format Transforming Encryption and Huffman Coding

Bence Kanyok

Bachelor Project in Software Engineering
The Mærsk Mc-Kinney Møller Institute
University of Southern Denmark

Supervised by Professor Lars Ramkilde Knudsen
June 2026

Read the original thesis (PDF)

Abstract

FTExfil is a proof-of-concept DNS tunneling tool for file transfer using Format Transforming Encryption (FTE) and character frequency shaping through Huffman coding. The project investigates whether these representations can reduce payload-level indicators associated with conventional tunnel encodings, particularly hostname entropy and recognizable Base32/Base64 patterns.

The implementation encrypts and authenticates file chunks, encodes them into DNS query names, and reconstructs the original file at an authoritative server. Evaluation using a 1 MiB test file compares Base32, regex-based FTE, and weighted Huffman encoding. Base32 achieved the highest throughput, followed by regex/FTE. Weighted encoding reduced measured hostname entropy to approximately 4.180 bits per character, compared with approximately 4.674 for regex/FTE, but required more DNS packets and longer transfer times.

The results demonstrate a trade-off between character distribution shaping and transmission overhead. Traffic-level indicators, such as query volume, remain unresolved. Reduced entropy does not establish successful evasion of real DNS tunneling detection systems; that evaluation is identified as future work.

Summary of the thesis abstract, Chapter 6, and Chapter 7. The original paper is available through the PDF link above.

Reading this project

The contents on the left separate the design, implementation, evaluation, and thesis sources. These pages summarize the supplied thesis and repositories, with references alongside the technical claims. Benchmark values and figures are taken from the original research.

Research disclaimer

This project is intended solely for academic research. The author does not condone unauthorized access, data exfiltration, or unlawful activity. FTExfil is a proof of concept, not a production-ready security tool.

Source: thesis front matter and Chapter 3.