Detection of DoH Traffic Tunnels Using Deep Learning for Encrypted Traffic Classification
-
Published:2023-02-22
Issue:3
Volume:12
Page:47
-
ISSN:2073-431X
-
Container-title:Computers
-
language:en
-
Short-container-title:Computers
Affiliation:
1. College of Computer Science and Engineering, Taibah University, Yanbu 42353, Saudi Arabia
Abstract
Currently, the primary concerns on the Internet are security and privacy, particularly in encrypted communications to prevent snooping and modification of Domain Name System (DNS) data by hackers who may attack using the HTTP protocol to gain illegal access to the information. DNS over HTTPS (DoH) is the new protocol that has made remarkable progress in encrypting Domain Name System traffic to prevent modifying DNS traffic and spying. To alleviate these challenges, this study explored the detection of DoH traffic tunnels of encrypted traffic, with the aim to determine the gained information through the use of HTTP. To implement the proposed work, state-of-the-art machine learning algorithms were used including Random Forest (RF), Gaussian Naive Bayes (GNB), Logistic Regression (LR), k-Nearest Neighbor (KNN), the Support Vector Classifier (SVC), Linear Discriminant Analysis (LDA), Decision Tree (DT), Adaboost, Gradient Boost (SGD), and LSTM neural networks. Moreover, ensemble models consisting of multiple base classifiers were utilized to carry out a series of experiments and conduct a comparative study. The CIRA-CIC-DoHBrw2020 dataset was used for experimentation. The experimental findings showed that the detection accuracy of the stacking model for binary classification was 99.99%. In the multiclass classification, the gradient boosting model scored maximum values of 90.71%, 90.71%, 90.87%, and 91.18% in Accuracy, Recall, Precision, and AUC. Moreover, the micro average ROC curve for the LSTM model scored 98%.
Subject
Computer Networks and Communications,Human-Computer Interaction
Reference42 articles.
1. Böttger, T., Cuadrado, F., Antichi, G., Fernandes, E.L., Tyson, G., Castro, I., and Uhlig, S. (2019, January 21–23). An Empirical Study of the Cost of DNS-over-HTTPS. Proceedings of the Internet Measurement Conference, Amsterdam, The Netherlands. 2. Borgolte, K., Chattopadhyay, T., Feamster, N., Kshirsagar, M., Holland, J., Hounsel, A., and Schmitt, P. (2019, January 20–21). How DNS over HTTPS is reshaping privacy, performance, and policy in the internet ecosystem. Proceedings of the TPRC47: The 47th Research Conference on Communication, Information and Internet Policy, Washington, DC, USA. 3. Analysis and Investigation of Malicious DNS Queries Using CIRA-CIC-DoHBrw-2020 Dataset;Jafar;Manch. J. Artif. Intell. Appl. Sci. (MJAIAS),2021 4. Bumanglag, K., and Kettani, H. (2020, January 9–12). On the Impact of DNS Over HTTPS Paradigm on Cyber Systems. Proceedings of the 2020 3rd International Conference on Information and Computer Technologies (ICICT), San Jose, CA, USA. 5. Siby, S., Juarez, M., Vallina-Rodriguez, N., and Troncoso, C. (2018, January 27). DNS Privacy not so private: The traffic analysis perspective. Proceedings of the 11th Workshop on Hot Topics in Privacy Enhancing Technologies (HotPETs 2018), Barcelona, Spain.
Cited by
4 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献
|
|