Author
Listed:
- Hardi Sabah Talabani
(Department of Computer Scince, College of Scinence, Charmo University, Sulaimaniyah, Chamchamal 46023, Iraq)
- Zrar Khalid Abdul
(Department of Computer Scince, College of Scinence, Charmo University, Sulaimaniyah, Chamchamal 46023, Iraq
Department of Software Engineering, Faculty of Engineering, Koya University, Koya 44023, Iraq)
- Hardi Mohammed Mohammed Saleh
(Department of Computer Scince, College of Scinence, Charmo University, Sulaimaniyah, Chamchamal 46023, Iraq)
Abstract
DNS over HTTPS (DoH) is an advanced version of the traditional DNS protocol that prevents eavesdropping and man-in-the-middle attacks by encrypting queries and responses. However, it introduces new challenges such as encrypted traffic communication, masking malicious activity, tunneling attacks, and complicating intrusion detection system (IDS) packet inspection. In contrast, unencrypted packets in the traditional Non-DoH version remain vulnerable to eavesdropping, privacy breaches, and spoofing. To address these challenges, an optimized dual-path feature selection approach is designed to select the most efficient packet features for binary class (DoH-Normal, DoH-Malicious) and multiclass (Non-DoH, DoH-Normal, DoH-Malicious) classification. Ant Colony Optimization (ACO) is integrated with machine learning algorithms such as XGBoost, K-Nearest Neighbors (KNN), Random Forest (RF), and Convolutional Neural Networks (CNNs) using CIRA-CIC-DoHBrw-2020 as the benchmark dataset. Experimental results show that the proposed model selects the most effective features for both scenarios, achieving the highest detection and outperforming previous studies in IDS. The highest accuracy obtained for binary and multiclass classifications was 0.9999 and 0.9955, respectively. The optimized feature set contributed significantly to reducing computational costs and processing time across all utilized classifiers. The results provide a robust, fast, and accurate solution to challenges associated with encrypted DNS packets.
Suggested Citation
Hardi Sabah Talabani & Zrar Khalid Abdul & Hardi Mohammed Mohammed Saleh, 2025.
"DNS over HTTPS Tunneling Detection System Based on Selected Features via Ant Colony Optimization,"
Future Internet, MDPI, vol. 17(5), pages 1-27, May.
Handle:
RePEc:gam:jftint:v:17:y:2025:i:5:p:211-:d:1650779
Download full text from publisher
Corrections
All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:gam:jftint:v:17:y:2025:i:5:p:211-:d:1650779. See general information about how to correct material in RePEc.
If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.
We have no bibliographic references for this item. You can help adding them by using this form .
If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.
For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: MDPI Indexing Manager (email available below). General contact details of provider: https://www.mdpi.com .
Please note that corrections may take a couple of weeks to filter through
the various RePEc services.