Detection of DoH Traffic Tunnels Using Deep Learning for Encrypted Traffic Classification

被引:4
|
作者
Alzighaibi, Ahmad Reda [1 ]
机构
[1] Taibah Univ, Coll Comp Sci & Engn, Yanbu 42353, Saudi Arabia
关键词
DNS over HTTPS (DoH); CIRA-CIC-DoHBrw-2020; deep Learning; encrypted traffic classification;
D O I
10.3390/computers12030047
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Currently, the primary concerns on the Internet are security and privacy, particularly in encrypted communications to prevent snooping and modification of Domain Name System (DNS) data by hackers who may attack using the HTTP protocol to gain illegal access to the information. DNS over HTTPS (DoH) is the new protocol that has made remarkable progress in encrypting Domain Name System traffic to prevent modifying DNS traffic and spying. To alleviate these challenges, this study explored the detection of DoH traffic tunnels of encrypted traffic, with the aim to determine the gained information through the use of HTTP. To implement the proposed work, state-of-the-art machine learning algorithms were used including Random Forest (RF), Gaussian Naive Bayes (GNB), Logistic Regression (LR), k-Nearest Neighbor (KNN), the Support Vector Classifier (SVC), Linear Discriminant Analysis (LDA), Decision Tree (DT), Adaboost, Gradient Boost (SGD), and LSTM neural networks. Moreover, ensemble models consisting of multiple base classifiers were utilized to carry out a series of experiments and conduct a comparative study. The CIRA-CIC-DoHBrw2020 dataset was used for experimentation. The experimental findings showed that the detection accuracy of the stacking model for binary classification was 99.99%. In the multiclass classification, the gradient boosting model scored maximum values of 90.71%, 90.71%, 90.87%, and 91.18% in Accuracy, Recall, Precision, and AUC. Moreover, the micro average ROC curve for the LSTM model scored 98%.
引用
收藏
页数:17
相关论文
共 50 条
  • [41] A Survey on Internet Encrypted Traffic Detection, Classification and Identification
    Chen, Zi-Han
    Cheng, Guang
    Xu, Zi-Heng
    Xu, Ke-Ya
    Qiu, Xing
    Niu, Dan-Dan
    [J]. Jisuanji Xuebao/Chinese Journal of Computers, 2023, 46 (05): : 1060 - 1085
  • [42] Novel Approach Using Deep Learning for Intrusion Detection and Classification of the Network Traffic
    Ahmad, Shahbaz
    Arif, Fahim
    Zabeehullah
    Iltaf, Naima
    [J]. 2020 IEEE INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND VIRTUAL ENVIRONMENTS FOR MEASUREMENT SYSTEMS AND APPLICATIONS (CIVEMSA 2020), 2020,
  • [43] Encrypted Network Traffic Classification and Resource Allocation with Deep Learning in Software Defined Network
    Setiawan, Roy
    Ganga, Ramakoteswara Rao
    Velayutham, Priya
    Thangavel, Kumaravel
    Sharma, Dilip Kumar
    Rajan, Regin
    Krishnamoorthy, Sujatha
    Sengan, Sudhakar
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2022, 127 (01) : 749 - 765
  • [44] An experimental study of different machine and deep learning techniques for classification of encrypted network traffic
    Obasi, ThankGod
    Shafiq, M. Omair
    [J]. 2020 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2020, : 4690 - 4699
  • [45] Deep Learning-Based Encrypted Network Traffic Classification and Resource Allocation in SDN
    Wu, Hao
    Zhang, Xi
    Yang, Jufeng
    [J]. JOURNAL OF WEB ENGINEERING, 2021, 20 (08): : 2319 - 2334
  • [46] Explaining Deep Learning Models for Per-packet Encrypted Network Traffic Classification
    Garcia, Luis
    Bartlett, Genevieve
    Ravi, Srivatsan
    Ibrahim, Harun
    Hardaker, Wes
    Kline, Erik
    [J]. 2022 IEEE INTERNATIONAL SYMPOSIUM ON MEASUREMENTS & NETWORKING (M&N 2022), 2022,
  • [47] Encrypted Network Traffic Classification and Resource Allocation with Deep Learning in Software Defined Network
    Roy Setiawan
    Ramakoteswara Rao Ganga
    Priya Velayutham
    Kumaravel Thangavel
    Dilip Kumar Sharma
    Regin Rajan
    Sujatha Krishnamoorthy
    Sudhakar Sengan
    [J]. Wireless Personal Communications, 2022, 127 : 749 - 765
  • [48] Datanet: Deep learning Based Encrypted Network Traffic Classification in SDN Home Gateway
    Wang, Pan
    Ye, Feng
    Chen, Xuejiao
    Qian, Yi
    [J]. IEEE ACCESS, 2018, 6 : 55380 - 55391
  • [49] End-to-end encrypted network traffic classification method based on deep learning
    Tian Shiming
    Gong Feixiang
    Mo Shuang
    Li Meng
    Wu Wenrui
    Xiao Ding
    [J]. The Journal of China Universities of Posts and Telecommunications, 2020, 27 (03) : 21 - 30
  • [50] Unveiling DoH tunnel: Toward generating a balanced DoH encrypted traffic dataset and profiling malicious behavior using inherently interpretable machine learning
    Niktabe, Sepideh
    Lashkari, Arash Habibi
    Roudsari, Arousha Haghighian
    [J]. PEER-TO-PEER NETWORKING AND APPLICATIONS, 2024, 17 (01) : 507 - 531