[HTML][HTML] A lightweight double-stage scheme to identify malicious DNS over HTTPS traffic using a hybrid learning approach

Q Abu Al-Haija, M Alohaly, A Odeh - Sensors, 2023 - mdpi.com
The Domain Name System (DNS) protocol essentially translates domain names to IP
addresses, enabling browsers to load and utilize Internet resources. Despite its major role …

[PDF][PDF] Detecting malicious dns over https traffic in domain name system using machine learning classifiers

YM Banadaki, S Robert - Journal of Computer Sciences and …, 2020 - researchgate.net
This paper presents a systematic two-layer approach for detecting DNS over HTTPS (DoH)
traffic and distinguishing Benign-DoH traffic from Malicious-DoH traffic using six machine …

Feature engineering and machine learning model comparison for malicious activity detection in the dns-over-https protocol

M Behnke, N Briner, D Cullen, K Schwerdtfeger… - IEEE …, 2021 - ieeexplore.ieee.org
The Domain Name System (DNS) is among the most ubiquitous and important protocols for
network communication; however, security concerns regarding DNS have been on the rise …

Doh insight: Detecting dns over https by machine learning

D Vekshin, K Hynek, T Cejka - … of the 15th International Conference on …, 2020 - dl.acm.org
Over the past few years, a new protocol DNS over HTTPS (DoH) has been created to
improve users' privacy on the internet. DoH can be used instead of traditional DNS for …

Detecting malicious dns over https traffic using machine learning

SK Singh, PK Roy - 2020 international conference on …, 2020 - ieeexplore.ieee.org
Network with the internet has grown-up very faster compared with any other technology
around the world. From the beginning of the Internet, the Domain name system (DNS) is an …

[HTML][HTML] DoH tunneling detection system for enterprise network using deep learning technique

TA Nguyen, M Park - Applied Sciences, 2022 - mdpi.com
In spite of protection mechanisms for Domain Name System (DNS), such as IP blacklist and
DNS Firewall, DNS still has privacy issues in reality, since DNS is a plain-text protocol …

Identifying malicious dns tunnel tools from doh traffic using hierarchical machine learning classification

R Mitsuhashi, A Satoh, Y Jin, K Iida… - … Conference, ISC 2021 …, 2021 - Springer
Although the DNS over HTTPS (DoH) protocol has desirable properties for Internet users
such as privacy and security, it also causes a problem in that network administrators are …

An explainable AI-based intrusion detection system for DNS over HTTPS (DoH) attacks

T Zebin, S Rezvy, Y Luo - IEEE Transactions on Information …, 2022 - ieeexplore.ieee.org
Over the past few years, Domain Name Service (DNS) remained a prime target for hackers
as it enables them to gain first entry into networks and gain access to data for exfiltration …

[PDF][PDF] Behavior Analysis based DNS Tunneling Detection and Classification with Big Data Technologies.

B Yu, L Smith, M Threefoot, FG Olumofin - IoTBD, 2016 - scitepress.org
Domain Name System (DNS) is ubiquitous in any network. DNS tunnelling is a technique to
transfer data, convey messages or conduct TCP activities over DNS protocol that is typically …

Classifying DNS tunneling tools for malicious DoH traffic

R Alenezi, SA Ludwig - 2021 IEEE Symposium Series on …, 2021 - ieeexplore.ieee.org
Cyber adversaries continuously seek new ways to penetrate security systems and infect
computer infrastructure. The past decade has witnessed a sharp increase in attacks …