Multi-Class DNS Attacks Classification using Deep Learning

dc.contributor.advisorFistum, Assamnew (PhD)
dc.contributor.authorTeshome, Assefa
dc.date.accessioned2022-02-10T04:46:23Z
dc.date.accessioned2023-11-04T15:13:03Z
dc.date.available2022-02-10T04:46:23Z
dc.date.available2023-11-04T15:13:03Z
dc.date.issued2021-01
dc.description.abstractNowadays, the number of Internet customers and data usage are increasing rapidly in Ethiopia and worldwide. One of the main components for providing internet services for customers is Domain Name System. It translates a domain name to IP address. It improves by introducing innovative architecture, interfaces, and protocols. It aids customers to simplify their services using these platforms. However, these have also opened new vulnerabilities on DNS. Thus it becomes the target of attackers. The attacker takes the advantage of openness to attack DNS such as DOS/DDOS, cache poisoning, Tunneling, Domain generating algorithms attack, and others. There are many implementations to detect DNS attacks. Recently, deep learning has emerged as an effective method for multi-class DNS attack detection and classification. We found that RNN classifiers improve DNS attack classification. They are good at dealing with sequential information. These classifiers’ performances were evaluated by calculating mean test accuracy, AUC-ROC, f1-score, and confusion matrix. We compared the performance of four different supervised deep learning classifiers, LSTM, GRU, BiGRU, and BiLSTM, on five-class DNS attacks. We selected the BIGRU model. The value of test accuracy and AUC of it are 97.18% and 0.9970 respectively. The performance of per class classifications by Ensemble model which we reviewed has been built less than BIGRU to classify ramnit and qakbot classes. F1-score of BIGRU to classify qakbot is greater than Ensemble model by 0.1666. And the same way, the F1-score of BIGRU to classify ramnit classes is also greater than the Ensemble model by 0.0798.en_US
dc.identifier.urihttp://etd.aau.edu.et/handle/123456789/29986
dc.language.isoen_USen_US
dc.publisherAddis Ababa Universityen_US
dc.subjectDomain Name Systemen_US
dc.subjectdeep learningen_US
dc.subjectRNNen_US
dc.subjectDOS/DDOSen_US
dc.subjectcache poisoningen_US
dc.subjectDNS Tunnelingen_US
dc.subjectDNS Amplificationen_US
dc.subjectramniten_US
dc.subjectqakboten_US
dc.titleMulti-Class DNS Attacks Classification using Deep Learningen_US
dc.typeThesisen_US

Files

Original bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
Teshome Assefa.pdf
Size:
1.59 MB
Format:
Adobe Portable Document Format
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.71 KB
Format:
Plain Text
Description: