EconPapers    
Economics at your fingertips  
 

DNS over HTTPS Tunneling Detection System Based on Selected Features via Ant Colony Optimization

Hardi Sabah Talabani (), Zrar Khalid Abdul and Hardi Mohammed Mohammed Saleh
Additional contact information
Hardi Sabah Talabani: Department of Computer Scince, College of Scinence, Charmo University, Sulaimaniyah, Chamchamal 46023, Iraq
Zrar Khalid Abdul: Department of Computer Scince, College of Scinence, Charmo University, Sulaimaniyah, Chamchamal 46023, Iraq
Hardi Mohammed Mohammed Saleh: Department of Computer Scince, College of Scinence, Charmo University, Sulaimaniyah, Chamchamal 46023, Iraq

Future Internet, 2025, vol. 17, issue 5, 1-27

Abstract: DNS over HTTPS (DoH) is an advanced version of the traditional DNS protocol that prevents eavesdropping and man-in-the-middle attacks by encrypting queries and responses. However, it introduces new challenges such as encrypted traffic communication, masking malicious activity, tunneling attacks, and complicating intrusion detection system (IDS) packet inspection. In contrast, unencrypted packets in the traditional Non-DoH version remain vulnerable to eavesdropping, privacy breaches, and spoofing. To address these challenges, an optimized dual-path feature selection approach is designed to select the most efficient packet features for binary class (DoH-Normal, DoH-Malicious) and multiclass (Non-DoH, DoH-Normal, DoH-Malicious) classification. Ant Colony Optimization (ACO) is integrated with machine learning algorithms such as XGBoost, K-Nearest Neighbors (KNN), Random Forest (RF), and Convolutional Neural Networks (CNNs) using CIRA-CIC-DoHBrw-2020 as the benchmark dataset. Experimental results show that the proposed model selects the most effective features for both scenarios, achieving the highest detection and outperforming previous studies in IDS. The highest accuracy obtained for binary and multiclass classifications was 0.9999 and 0.9955, respectively. The optimized feature set contributed significantly to reducing computational costs and processing time across all utilized classifiers. The results provide a robust, fast, and accurate solution to challenges associated with encrypted DNS packets.

Keywords: intrusion detection system; DNS over HTTPS; ant colony optimization; feature selection; dimensionality reduction; machine learning (search for similar items in EconPapers)
JEL-codes: O3 (search for similar items in EconPapers)
Date: 2025
References: Add references at CitEc
Citations:

Downloads: (external link)
https://www.mdpi.com/1999-5903/17/5/211/pdf (application/pdf)
https://www.mdpi.com/1999-5903/17/5/211/ (text/html)

Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.

Export reference: BibTeX RIS (EndNote, ProCite, RefMan) HTML/Text

Persistent link: https://EconPapers.repec.org/RePEc:gam:jftint:v:17:y:2025:i:5:p:211-:d:1650779

Access Statistics for this article

Future Internet is currently edited by Ms. Grace You

More articles in Future Internet from MDPI
Bibliographic data for series maintained by MDPI Indexing Manager ().

 
Page updated 2025-05-08
Handle: RePEc:gam:jftint:v:17:y:2025:i:5:p:211-:d:1650779