With increasing security awareness among netizens, DNS over HTTPS (DoH) has been developed and has gradually become a widely recognized privacy protection technology. DoH transmits DNS requests through encrypted HTTPS channels, effectively preventing eavesdropping or tampering by third parties. However, attackers exploit the obscurity of DoH to conduct malicious attacks, posing significant threats to cyberspace security. In this paper, we propose a residual network, HAResNet, based on hybrid attention mechanisms for efficient detection of malicious DoH traffic. The hybrid attention mechanism enhances feature representation across multiple scales and dimensions, facilitating the capture of complex contextual dependencies. To address the issue of an imbalanced network environment, we developed FCE loss, which prioritizes minority-class samples and difficult-to-classify cases. Experimental results demonstrate that our model achieves a high detection rate of 99.23% and a low false alarm rate of 0.08% on public datasets. To interpret the model’s decisions, we employed SHAP to perform global and local feature importance analysis, as well as feature contribution analysis.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

An Explainable Detection Model for Malicious DoH Traffic Based on Hybrid Attention

  • Yishan Yang,
  • Dong-Jiu Liu,
  • Guang-Gang Geng,
  • Yinyan Zhang

摘要

With increasing security awareness among netizens, DNS over HTTPS (DoH) has been developed and has gradually become a widely recognized privacy protection technology. DoH transmits DNS requests through encrypted HTTPS channels, effectively preventing eavesdropping or tampering by third parties. However, attackers exploit the obscurity of DoH to conduct malicious attacks, posing significant threats to cyberspace security. In this paper, we propose a residual network, HAResNet, based on hybrid attention mechanisms for efficient detection of malicious DoH traffic. The hybrid attention mechanism enhances feature representation across multiple scales and dimensions, facilitating the capture of complex contextual dependencies. To address the issue of an imbalanced network environment, we developed FCE loss, which prioritizes minority-class samples and difficult-to-classify cases. Experimental results demonstrate that our model achieves a high detection rate of 99.23% and a low false alarm rate of 0.08% on public datasets. To interpret the model’s decisions, we employed SHAP to perform global and local feature importance analysis, as well as feature contribution analysis.