TY - GEN
T1 - Detecting Malicious DNS over HTTPS Traffic Using Machine Learning
AU - Singh, Sunil Kumar
AU - Roy, Pradeep Kumar
N1 - Publisher Copyright:
© 2020 IEEE.
PY - 2020/12/20
Y1 - 2020/12/20
N2 - Network with the internet has grown-up very faster compared with any other technology around the world. From the beginning of the Internet, the Domain name system (DNS) is an integral and important part of it. The primary task of DNS is to redirect the users at correct computers, applications, and files by mapping IP and domain name. Due to certain security flaws of DNS, it is always a major attack target for attackers like DNSbased malware, DNS-amplification, false-positive triggering, DNS tunneling, etc. DNS over TLS (DoT) and DNS over HTTPS (DoH) are recently developed and deployed by Google and Cloudflare to prevent these types of attacks. DoT and DoH are the standard protocols which mainly designed for privacy and security by encrypting the DNS traffic between users and DNS resolver servers. This paper uses various machine learning classifiers such as (i) Naive Bayes (NB), ii) Logistic Regression (LR), iii) Random Forest (RF), (iv) K-Nearest Neighbor (KNN), and (v) Gradient Boosting (GB) to detect the malicious activity at DNS level in the DoH environment. The experiments are conducted on a benchmark MoH dataset (CIRA-CIC-DoHBrw-2020). Several features are used to develop a robust model. The experimental outcome confirmed that the RF and GB classifiers are better choices for the said problem. Since, majority of the malicious activity detected by the developed model, it can be said that the ML-based algorithms are a better option for the prevention of DNS attacks on DoH traffic.
AB - Network with the internet has grown-up very faster compared with any other technology around the world. From the beginning of the Internet, the Domain name system (DNS) is an integral and important part of it. The primary task of DNS is to redirect the users at correct computers, applications, and files by mapping IP and domain name. Due to certain security flaws of DNS, it is always a major attack target for attackers like DNSbased malware, DNS-amplification, false-positive triggering, DNS tunneling, etc. DNS over TLS (DoT) and DNS over HTTPS (DoH) are recently developed and deployed by Google and Cloudflare to prevent these types of attacks. DoT and DoH are the standard protocols which mainly designed for privacy and security by encrypting the DNS traffic between users and DNS resolver servers. This paper uses various machine learning classifiers such as (i) Naive Bayes (NB), ii) Logistic Regression (LR), iii) Random Forest (RF), (iv) K-Nearest Neighbor (KNN), and (v) Gradient Boosting (GB) to detect the malicious activity at DNS level in the DoH environment. The experiments are conducted on a benchmark MoH dataset (CIRA-CIC-DoHBrw-2020). Several features are used to develop a robust model. The experimental outcome confirmed that the RF and GB classifiers are better choices for the said problem. Since, majority of the malicious activity detected by the developed model, it can be said that the ML-based algorithms are a better option for the prevention of DNS attacks on DoH traffic.
UR - https://www.scopus.com/pages/publications/85100262278
UR - https://www.scopus.com/pages/publications/85100262278#tab=citedBy
U2 - 10.1109/3ICT51146.2020.9312004
DO - 10.1109/3ICT51146.2020.9312004
M3 - Conference contribution
AN - SCOPUS:85100262278
T3 - 2020 International Conference on Innovation and Intelligence for Informatics, Computing and Technologies, 3ICT 2020
BT - 2020 International Conference on Innovation and Intelligence for Informatics, Computing and Technologies, 3ICT 2020
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 2020 International Conference on Innovation and Intelligence for Informatics, Computing and Technologies, 3ICT 2020
Y2 - 20 December 2020 through 21 December 2020
ER -