article · Data Science and Management
Domain name system (DNS) tunneling attacks can bypass firewalls, which typically “trust” DNS transmissions by concealing malicious traffic in the packets trusted to convey legitimate ones, thereby making detection using conventional security techniques challenging. To address this issue, we propose a Lebesgue-2 regularized multilayer perceptron (L2R-MLP) algorithm for detecting DNS tunneling attacks. The DNS dataset was carefully curated from a publicly available repository, and relevant features, such as packet size and count, were selected using the recusive feature elimination technique. L2 regularization in the MLP classifier's hidden layers enhances pattern recognition during training, effectively countering the risk of overfitting. When evaluated against a benchmark MLP model, L2R-MLP demonstrated superior performance with 99.46% accuracy, 97.00% precision, 97.00% F1-score, 99.95% recall, and an AUC of 89.00%. In comparison, the benchmark MLP achieved 92.53% accuracy, 96.00% precision, 97.00% F1-score, 99.95% recall, and an AUC of 87.00%. This highlights the effectiveness of L2 regularization in improving predictive capabilities and model generalization for unseen instances. • A Regularized multilabel MLP model for the detection of DNS Tunneling, referred to as L2R-MLP is presented. • Introduces a cutting-edge method for detecting DNS tunnels by utilizing a unique multilabel classification scheme. • Presents Multilabel classification as against the traditional methods that typically concentrate on binary classifications. • Incorporates L2 regularization to mitigate overfitting, enhance the model's robustness, reliability and detection abilities. • The proposed technique (L2R-MLP) consistently outperformed the generic MLP model both in accuracy and precision.
This page summarises published work. The authoritative version sits with the publisher.
DOI: 10.1016/j.dsm.2024.10.005
Is something wrong with this record? Report it or request removal.
Discussion
Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.
No discussion yet. Open the first thread.
New to MARATTO™? Create a free account.