Skip to main navigation Skip to search Skip to main content

Detecting Malicious DNS over HTTPS Traffic Using Machine Learning

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Network with the internet has grown-up very faster compared with any other technology around the world. From the beginning of the Internet, the Domain name system (DNS) is an integral and important part of it. The primary task of DNS is to redirect the users at correct computers, applications, and files by mapping IP and domain name. Due to certain security flaws of DNS, it is always a major attack target for attackers like DNSbased malware, DNS-amplification, false-positive triggering, DNS tunneling, etc. DNS over TLS (DoT) and DNS over HTTPS (DoH) are recently developed and deployed by Google and Cloudflare to prevent these types of attacks. DoT and DoH are the standard protocols which mainly designed for privacy and security by encrypting the DNS traffic between users and DNS resolver servers. This paper uses various machine learning classifiers such as (i) Naive Bayes (NB), ii) Logistic Regression (LR), iii) Random Forest (RF), (iv) K-Nearest Neighbor (KNN), and (v) Gradient Boosting (GB) to detect the malicious activity at DNS level in the DoH environment. The experiments are conducted on a benchmark MoH dataset (CIRA-CIC-DoHBrw-2020). Several features are used to develop a robust model. The experimental outcome confirmed that the RF and GB classifiers are better choices for the said problem. Since, majority of the malicious activity detected by the developed model, it can be said that the ML-based algorithms are a better option for the prevention of DNS attacks on DoH traffic.

Original languageEnglish
Title of host publication2020 International Conference on Innovation and Intelligence for Informatics, Computing and Technologies, 3ICT 2020
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9781728196732
DOIs
Publication statusPublished - 20-12-2020
Event2020 International Conference on Innovation and Intelligence for Informatics, Computing and Technologies, 3ICT 2020 - Sakheer, Bahrain
Duration: 20-12-202021-12-2020

Publication series

Name2020 International Conference on Innovation and Intelligence for Informatics, Computing and Technologies, 3ICT 2020

Conference

Conference2020 International Conference on Innovation and Intelligence for Informatics, Computing and Technologies, 3ICT 2020
Country/TerritoryBahrain
CitySakheer
Period20-12-2021-12-20

All Science Journal Classification (ASJC) codes

  • Artificial Intelligence
  • Computer Science Applications
  • Information Systems

Fingerprint

Dive into the research topics of 'Detecting Malicious DNS over HTTPS Traffic Using Machine Learning'. Together they form a unique fingerprint.

Cite this