返回
An Explainable AI-Based Intrusion Detection System for DNS Over HTTPS (DoH) Attacks
DOI:10.1109/TIFS.2022.3183390.png)
摘要
En 中文
Over the past few years, Domain Name Service (DNS) remained a prime target for hackers as it enables them to gain first entry into networks and gain access to data for exfiltration. Although the DNS over HTTPS (DoH) protocol has desirable properties for internet users such as privacy and security, it also causes a problem in that network administrators are prevented from detecting suspicious network traffic generated by malware and malicious tools. To support their efforts in maintaining a secure network, in this paper, we have implemented an explainable AI solution using a novel machine learning framework. We have used the publicly available CIRA-CIC-DoHBrw-2020 dataset for developing an accurate solution to detect and classify the DNS over HTTPS attacks. Our proposed balanced and stacked Random Forest achieved very high precision (99.91%), recall (99.92%) and F1 score (99.91%) for the classification task at hand. Using explainable AI methods, we have additionally highlighted the underlying feature contributions in an attempt to provide transparent and explainable results from the model.
Keyword:
Tunneling
Servers
Security
Cryptography
Protocols
Computer crime
Feature extraction
Secure computing
machine learning
intrusion detection system
explainable AI
期刊
IF:
8
论文数:
5.3K
被引数:
2.3W
机构
引用论文
DNS-ADVP: A Machine Learning Anomaly Detection and Visual Platform to Protect Top-Level Domain Name Servers Against DDoS AttacksDns-advp: 一个机器学习异常检测和可视化平台,用于保护顶级域名服务器免受DDoS攻击
IEEE ACCESS
IF3.6
Feature Engineering and Machine Learning Model Comparison for Malicious Activity Detection in the DNS-Over-HTTPS Protocol
IEEE ACCESS
IF3.6

