ENTROPY TRACE · HISTOGRAM · ROC SWEEP

DNS Tunneling Entropy Analytics (2D)

DNS tunneling smuggles stolen data out of a network inside ordinary-looking DNS queries, one of the quieter techniques behind real cyber-espionage campaigns because DNS traffic is rarely filtered at the firewall. This dashboard streams two classes of query — legitimate hostnames and base32-encoded exfiltration labels — through the same entropy calculation and threshold test as a real entropy-based DNS security control, then renders the detector statistically: a scrolling entropy-over-time trace, a live overlaid histogram of benign vs. tunnel entropy with a threshold you can drag by hand, and a genuine sweep-computed ROC curve tracing the whole detection-rate / false-positive-rate trade-off as you retune it.