Malicious domains pose a significant threat to internet security, with cyber-criminals exploiting the Domain Name System (DNS) to deceive users and host malicious content. The DNS services are very significant, and hence, the DNS traffic cannot be blocked. This situation is exploited by establishing a covert tunnel for communicating commands by the malicious server, thereby taking over the control of the compromised machine. Traditional methods of detecting malicious domains, such as blacklisting, have limitations in detecting newly generated domains. In this paper, we suggest a DNS intrusion detection system using ensemble learning, where we also use the Local Interpretable Model-agnostic Explanations (LIME) to further understand the predictions of the model. For evaluating the model, the CIC-Bell-DNS2021 dataset was used. To validate the generalizability of the model, we also check it on the UNSW-NB15 dataset. The Experiments show that the proposed method outperforms the state-of-the-art results on two datasets, CIC-Bell-DNS2021 and UNSW-NB15.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Interpretable Ensemble Learning Model for Enabling an IDS to Detect DNS Attacks

  • Loreen Mahmoud,
  • Sreedev Pillai,
  • Sugata Gangopadhyay

摘要

Malicious domains pose a significant threat to internet security, with cyber-criminals exploiting the Domain Name System (DNS) to deceive users and host malicious content. The DNS services are very significant, and hence, the DNS traffic cannot be blocked. This situation is exploited by establishing a covert tunnel for communicating commands by the malicious server, thereby taking over the control of the compromised machine. Traditional methods of detecting malicious domains, such as blacklisting, have limitations in detecting newly generated domains. In this paper, we suggest a DNS intrusion detection system using ensemble learning, where we also use the Local Interpretable Model-agnostic Explanations (LIME) to further understand the predictions of the model. For evaluating the model, the CIC-Bell-DNS2021 dataset was used. To validate the generalizability of the model, we also check it on the UNSW-NB15 dataset. The Experiments show that the proposed method outperforms the state-of-the-art results on two datasets, CIC-Bell-DNS2021 and UNSW-NB15.