Effective analysis of Domain Name System (DNS) traffic is crucial for enhancing network security and optimizing performance in modern IT infrastructures. This research focuses on leveraging eXplainable Artificial Intelligence (XAI) techniques to derive actionable insights from DNS traffic data collected from recursive resolvers. DNS traffic analysis plays a pivotal role in detecting and mitigating potential security threats such as malware downloads, data exfiltration attempts, and phishing attacks. Traditional methods often lack the ability to provide clear explanations for their findings, making it challenging for network administrators and cybersecurity professionals to fully trust and act upon the results. XAI addresses this limitation by offering models that not only predict anomalies but also provide interpretable explanations for these findings. This transparency is essential for building trust and understanding in automated decision-making processes within cybersecurity operations. Our approach involves applying state-of-the-art machine learning algorithms to analyze DNS query patterns and identify anomalous behaviors indicative of security incidents. By integrating XAI into our methodology, we aim to enhance the accuracy of anomaly detection and reduce false positives, thereby enabling more effective and proactive cybersecurity measures. Through empirical evaluations using real-world DNS traffic datasets, we demonstrate the effectiveness of our approach in improving the detection of malicious activities while maintaining high levels of accuracy and reliability. We also discuss the practical implications of our findings for network management and cybersecurity operations, emphasizing the importance of transparent and interpretable AI-driven solutions in enhancing overall cyber resilience.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Leveraging DNS Traffic Analysis for Threat Detection Using Explainable AI

  • Shubham Goyal,
  • Swati Singh,
  • Gopinath Palaniappan,
  • Balaji Rajendran,
  • S. D. Sudarsan

摘要

Effective analysis of Domain Name System (DNS) traffic is crucial for enhancing network security and optimizing performance in modern IT infrastructures. This research focuses on leveraging eXplainable Artificial Intelligence (XAI) techniques to derive actionable insights from DNS traffic data collected from recursive resolvers. DNS traffic analysis plays a pivotal role in detecting and mitigating potential security threats such as malware downloads, data exfiltration attempts, and phishing attacks. Traditional methods often lack the ability to provide clear explanations for their findings, making it challenging for network administrators and cybersecurity professionals to fully trust and act upon the results. XAI addresses this limitation by offering models that not only predict anomalies but also provide interpretable explanations for these findings. This transparency is essential for building trust and understanding in automated decision-making processes within cybersecurity operations. Our approach involves applying state-of-the-art machine learning algorithms to analyze DNS query patterns and identify anomalous behaviors indicative of security incidents. By integrating XAI into our methodology, we aim to enhance the accuracy of anomaly detection and reduce false positives, thereby enabling more effective and proactive cybersecurity measures. Through empirical evaluations using real-world DNS traffic datasets, we demonstrate the effectiveness of our approach in improving the detection of malicious activities while maintaining high levels of accuracy and reliability. We also discuss the practical implications of our findings for network management and cybersecurity operations, emphasizing the importance of transparent and interpretable AI-driven solutions in enhancing overall cyber resilience.