Please use this identifier to cite or link to this item: http://localhost:8081/jspui/handle/123456789/21577
Full metadata record
DC FieldValueLanguage
dc.contributor.authorPillai, Sreedev-
dc.date.accessioned2026-09-20T07:11:39Z-
dc.date.available2026-09-20T07:11:39Z-
dc.date.issued2023-05-
dc.identifier.urihttp://localhost:8081/jspui/handle/123456789/21577-
dc.guideGangopadhyay, Sugataen_US
dc.description.abstractMalicious domains remain a major threat to the security of the internet, with cyber-criminals exploiting the Domain Name System (DNS) to deceive users into accessing malicious websites hosting malware, phishing schemes, botnets, or spam messages. The resulting impact on cor porations can be devastating, often resulting in significant financial losses from a single attack. According to recent statistics, the frequency of malicious domain attacks has increased sub stantially in recent years, with cyber-criminals employing increasingly sophisticated techniques to evade detection. As a result, timely identification and classification of malicious domains are more critical than ever to prevent such attacks from causing harm. In the past, the only method of detecting malicious domains was by filtering them against blacklists. Now, recent ML techniques are used to enhance the effectiveness of IDS. By leveraging machine learning algorithms, these systems can better detect patterns and anomalies in domain names, allowing them to identify potentially malicious domains more accurately. By selecting and extracting relevant features from domain data, machine learning algorithms can better understand the characteristics of malicious domains and distinguish them from legitimate ones. In simulating real-world scenarios, the ratio of benign to malicious domains is a critical factor. Typically, around 99% of internet traffic is directed toward benign domains, while only a small fraction is directed toward malicious domains. CIRA-CIC-DoHBrw-2020 dataset, being one of the latest was tested to core right from ML models to Deep Learning Models and results obtained were satisfactory. The mammoth dataset comprising of more than 6 lac instances or rows against 28 features stood tall in deriving out various analysis out of the behaviour of various models on negotiating this dataset. Another feature which is pertinent to mention is that this dataset is also useful for designing systems to work against modern threats which are even bypassing DNS over HTTPS (DoH) protection. DNS vulnerabilities related to privacy and data manipulation was safeguarded using the DoH protocol, that enhances privacy and combats eavesdropping and man-in-the-middle attacks. The basic ML models were applied and Random Forest (RF) gave the best result of 99%. The dataset was also exposed to mechanism of Logical Analysis of Data (LAD) wherein it delivered an commendable 96% result. Recurrent Neural Network (RNN) was also experimented but it failed to deliver substantial results. Convolutional Neural Networks (CNN), finally delivered outstanding results with 99.9%. The IDS developed using these models as base stands a high chance of providing the necessary protection mechanism.This approach is crucial for developing effective Intrusion Detection System that can adapt to new threats and stay ahead of cyber criminals.en_US
dc.language.isoenen_US
dc.publisherIIT Roorkeeen_US
dc.titleAI-Based Models For Enabling An Intrusion Detection System To Detect DNS Attacksen_US
dc.typeDissertationsen_US
Appears in Collections:MASTERS' THESES (CSE)

Files in This Item:
File Description SizeFormat 
21535030_Sreedev Pillai.pdf3.47 MBAdobe PDFView/Open


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.