arrow
Return

An Explainable AI-Based Intrusion Detection System for DNS Over HTTPS (DoH) Attacks

delete2022-01-01
delete66
delete
OA
AI
T
Tahmina Zebin *
S
Shahadate Rezvy
Y
Yuan Luo
DOI:10.1109/TIFS.2022.3183390delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Over the past few years, Domain Name Service (DNS) remained a prime target for hackers as it enables them to gain first entry into networks and gain access to data for exfiltration. Although the DNS over HTTPS (DoH) protocol has desirable properties for internet users such as privacy and security, it also causes a problem in that network administrators are prevented from detecting suspicious network traffic generated by malware and malicious tools. To support their efforts in maintaining a secure network, in this paper, we have implemented an explainable AI solution using a novel machine learning framework. We have used the publicly available CIRA-CIC-DoHBrw-2020 dataset for developing an accurate solution to detect and classify the DNS over HTTPS attacks. Our proposed balanced and stacked Random Forest achieved very high precision (99.91%), recall (99.92%) and F1 score (99.91%) for the classification task at hand. Using explainable AI methods, we have additionally highlighted the underlying feature contributions in an attempt to provide transparent and explainable results from the model.
Keywords:
Tunneling
Servers
Security
Cryptography
Protocols
Computer crime
Feature extraction
Secure computing
machine learning
intrusion detection system
explainable AI

Journal

IEEE Transactions on Information Forensics and Security cover
IEEE Transactions on Information Forensics and Security
IF:
8
Papers:
5.3K
Citations:
2.3W

Organization

U
University of East Anglia
Scholars:
9.6K
Papers: 1.0W
Citations: 1.8W
U
university of york - uk
Scholars:
1.5W
Papers: 1.5W
Citations: 15
Y
york saint john university
Scholars:
367
Papers: 397
Citations: 0
researcher View more organizations
Cited Papers

Cited Papers

DNS-ADVP: A Machine Learning Anomaly Detection and Visual Platform to Protect Top-Level Domain Name Servers Against DDoS Attacks
err2019-01-01
err14
errOAAI
errTrejo, Luis A.; Ferman, Victor; Angel Medina-Perez, Miguel; Arredondo Giacinti, Fernando Miguel; Monroy, Raul; Ramirez-Marquez, Jose E.
errShare
errSave
Feature Engineering and Machine Learning Model Comparison for Malicious Activity Detection in the DNS-Over-HTTPS Protocol
err2021-01-01
err21
errOAAI
errBehnke, Matthew; Briner, Nathan; Cullen, Drake; Schwerdtfeger, Katelynn; Warren, Jackson; Basnet, Ram; Doleck, Tenzin
errShare
errSave
errShare
errSave
researcher View more