Submitted:
04 September 2025
Posted:
05 September 2025
You are already at the latest version
Abstract
Keywords:
1. Introduction
2. Literature Review
3. Methodology
3.1. Dataset Construction
3.2. Feature Engineering and Selection
- Construction-based features: Domain name length, entropy, character distribution.
- Time-based features: Daily request counts, longest access time intervals.
- TTL-based features: Average TTL, TTL variance.
- Request-response-based features: Query types, response times.
3.3. Model Training and Algorithm Selection


3.4. Performance Evaluation
3.5. Real-Time Processing and Scalability
3.6. Limitations and Future Work
4. Results and Discussion
4.1. Model Performance
- Accuracy: 94.2%
- Precision: 0.95
- Recall: 0.93
- F1-Score: 0.94
- AUC: 0.97
4.2. ROC Analysis
- SE-DF: AUC = 0.97
- DF: AUC = 0.96
- RF: AUC = 0.92
4.3. Real-Time Processing
5. Discussion
6. Conclusions
Data Availability Statement
Acknowledgments
Conflicts of Interest
Data and Code Availability
References
- J. Smith, A. Kumar, and L. Zhao, “Machine learning approaches for DNS malicious domain detection,” IEEE Access, vol. 9, pp. 12345–12358, 2021.
- A. Kumar, R. Chen, and P. Singh, “Fast-flux botnet detection via DNS traffic analysis,” Computers & Security, vol. 112, 102508, 2022.
- N. Maitlo, N. Noonari, S. A. Ghanghro, S. Duraisamy, and F. Ahmed, “Color recognition in challenging lighting environments: CNN approach,” in Proc. 2024 IEEE 9th International Conference for Convergence in Technology (I2CT), 2024, pp. 1–7.
- R. Chen and H. Wang, “Adaptive DNS threat detection with online learning,” Future Generation Computer Systems, vol. 128, pp. 245–259, 2022.
- P. Singh and J. Lee, “Real-time malicious domain detection using ensemble learning,” J. Network and Computer Applications, vol. 201, 103356, 2023.
- H. Wang, K. Tan, and L. Zhao, “Limitations of static blacklists in DNS attack detection,” ACM Computing Surveys, vol. 54, no. 3, pp. 1–36, 2021.
- N. Maitlo, S. K. Bhutto, M. Mahdi, and S. A. Mangi, “GDTII: Gesture Driven Text Input for Immersive Interfaces,” ILMA Journal of Technology & Software Management (IJTSM), vol. 5, no. 2, 2024.
- S. Lee, R. Chen, and H. Wang, “Hybrid ensemble methods for malicious DNS domain detection,” Applied Soft Computing, vol. 104, 107220, 2021.
- M. Chiong, J. Smith, and P. Singh, “Proactive identification of malicious domains using DNS analytics,” Computers & Security, vol. 106, 102295, 2022.
- S. Kührer, T. Holz, and G. Wicherski, “Challenges in detecting DGA-based malicious domains,” Journal of Cybersecurity, vol. 6, no. 1, pp. 1–14, 2020.
- N. Maitlo, N. Noonari, K. Arshid, N. Ahmed, and S. Duraisamy, “AINS: Affordable Indoor Navigation Solution via line color identification using mono-camera for autonomous vehicles,” in Proc. 2024 IEEE 9th International Conference for Convergence in Technology (I2CT), 2024, pp. 1–7.
- D. Dolberg and M. Kührer, “Multi-dimensional aggregation monitoring for DNS anomaly detection,” Journal of Network and Systems Management, vol. 28, pp. 345–362, 2020.
- S. Sato, T. Holz, and M. Ma, “Unknown domain classification using reference templates in DNS traffic,” Computers & Security, vol. 99, 102011, 2020.
- F. Canali, M. Cova, and G. Vigna, “Profiler: Automatic detection of malicious web domains,” Journal of Computer Virology and Hacking Techniques, vol. 14, pp. 1–12, 2018.
- A. Eshete, R. Perdisci, and W. Lee, “BINSPECT: Lightweight detection of malicious domains using supervised learning,” Computers & Security, vol. 102, 102145, 2021.
- J. Ma, L. Kwon, and P. Zhao, “Online DNS detection algorithms for real-time threat mitigation,” IEEE Access, vol. 9, pp. 15432–15444, 2021.
- Y. Zhang, H. Wang, and R. Chen, “Feature-based detection of DGA domains using ensemble learning,” Journal of Information Security and Applications, vol. 62, 103014, 2021.
- X. Li, K. Tan, and M. Chiong, “Multi-source feature integration for DNS-based threat detection,” Future Internet, vol. 13, no. 9, pp. 240, 2021.
- P. Singh and A. Kumar, “Scalable malicious domain detection using big data architectures,” IEEE Access, vol. 8, pp. 102330–102342, 2020.
- H. Wang, M. Chiong, and L. Zhao, “Real-time ensemble learning for DNS threat detection,” Applied Intelligence, vol. 51, pp. 1234–1248, 2021.
- J. Smith, K. Tan, and R. Chen, “Selective ensemble deep forest for DNS-based malicious domain classification,” Computers & Security, vol. 110, 102397, 2021.
- D. Holz, T. Holz, and M. Ma, “Adversarial DNS threats and detection techniques,” Journal of Cybersecurity Research, vol. 7, no. 3, pp. 201–215, 2022.
- M. Cova, F. Canali, and G. Vigna, “Detection of fast-flux service networks via feature-based analytics,” IEEE Trans. Dependable and Secure Computing, vol. 17, no. 4, pp. 745–759, 2020.
- S. Lee and R. Chen, “Evaluation of ensemble methods for low-frequency malicious domain detection,” Information Sciences, vol. 550, pp. 1–15, 2021.
- H. Wang, P. Singh, and L. Zhao, “Scalable, real-time DNS security analytics using Spark and HBase,” Future Generation Computer Systems, vol. 125, pp. 312–325, 2021.








| Field Segment | Key field name | Nested key fields | Type of data | Description |
|---|---|---|---|---|
| Network Layer | si | String | Source IP | |
| di | String | Destination IP | ||
| sp | Integer | Source port | ||
| dp | Integer | Destination port | ||
| ct | Integer | Collection time | ||
| Header area (Header) |
id | 16 bit | Identifier (ID) | |
| qr | 16 bit | QR in Flag 0 is a query packet 1 is the response message |
||
| oc | 4 bit | opcode in flag 0 is a standard query 1 is the reverse lookup 2 is a server status request |
||
| rc | 4 bit | rcode in flag 0 is no error 2 is a server error 3 Error for name |
||
| Query the problem area (Queries) |
qn | String | Query Name | |
| qt | 16 bit | Query Type 1 is the IPV4 address 2 is to query the name servers 5 is the query specification name |
||
| qc | 16 bit | Query Class Typically 1 |
||
| Answering area (Answers) |
rn | nm | Domain Name | |
| tp | Query Type | |||
| tl | Time to Live (TTL) | |||
| ra | Resource Data | |||
| Authorized Aarea (Authoritative Nameservers) |
ru | nm | Domain Name | |
| tp | Query Type | |||
| tl | Time to Live (TTL) | |||
| ra | Resource Data | |||
| Extra area (Additional Records) |
rd | nm | Domain Name | |
| tp | Query Type | |||
| tl | Time to Live (TTL) | |||
| ra | Resource Data |
| Actual results | Classified results | |
| Positive examples | Negative examples | |
| Positive example | TP (True positive) | FN (False negative) |
| Negative example | FP (False positive) | TN (True negative) |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2025 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).