Detection of DNS Spoofing Attacks on Campus Networks Using LightGBM with Hybrid Feature Selection (SelectKBest + SHAP)

Authors

  • Arie Budiansyah Universitas Syiah Kuala, Indonesia
  • Rudi Arif Candra Politeknik Aceh Selatan, Indonesia
  • Dirja Nur Ilham Politeknik Aceh Selatan, Indonesia
  • Alim Misbullah Universitas Syiah Kuala, Indonesia

DOI:

https://doi.org/10.47709/brilliance.v5i1.5962

Keywords:

DNS Spoofing, DNS over HTTPS, CIRA-CIC-DoHBrw-2020 dataset, Feature Selection, Elbow Method, Kneedle Method, LightGBM, Machine Learning, Network Security, Cybersecurity

Abstract

This study investigates the detection of Domain Name System over HTTPS (DoH) spoofing attacks utilizing the CIRA-CIC-DoHBrw-2020 dataset, which encompasses over 100,000 labeled DNS records categorized as either normal or malicious. Features such as packet timing, packet size, and TLS parameters are utilized for detection purposes. A systematic feature selection process is conducted utilizing the Elbow and Kneedle methods based on F-Score values derived from a built-in model evaluation. This method ensures that the top features are selected objectively and quantitatively, thereby enhancing the robustness of the model. The model is trained using the five most significant features, yielding exceptional performance metrics: a training time of just 0.5727 seconds, an inference time of 0.0157 seconds, and an inference latency of 0.0035 milliseconds per sample. Moreover, the model delivers an outstanding accuracy of 0.9995, an F1-Score of 0.9995, and an AUC-ROC of 1.0000, reflecting near-perfect detection capabilities. The classification report reveals a balanced distribution of precision, recall, and F1-Scores of 1.00 across both normal and malicious classes, based on a test sample of 14,974 entries. The Elbow plot visually confirms the optimal number of features utilized, while the SHAP beeswarm plot provides insights into how each selected feature contributes to the model’s predictions, facilitating interpretability. Additionally, the confusion matrix corroborates the model's reliability, showcasing that nearly all samples were accurately classified. The results demonstrate that the proposed methodology significantly enhances the effectiveness of DNS spoofing detection, offering a promising avenue for securing DNS over HTTPS communications.

References

Ajisafe, T. (2021). Developing Cardiometabolic Risk Classifiers for Youth Using Handgrip Strength, Anthropometrics, and Demographics: A Machine Learning Approach Leveraging National Health and Nutrition Examination Survey Data. https://doi.org/10.21203/rs.3.rs-488747/v1

Alawi, A. M. A., Shuaili, H. H. A., Al?Naamani, K., Naamani, Z. A., & Al?Busafi, S. A. (2024). A Machine Learning-Based Mortality Prediction Model for Patients With Chronic Hepatitis C Infection: An Exploratory Study. Journal of Clinical Medicine, 13(10), 2939. https://doi.org/10.3390/jcm13102939

Almusallam, A. (2021). Feature Engineering and Machine Learning Model Comparison for Malicious Activity Detection in the DNS-Over-HTTPS Protocol. IEEE Access, 9, 132159–132174.

Alshamrani, A. (2024). FSDC: Flow Samples and Dimensions Compression for Efficient Detection of DNS-over-HTTPS Tunnels. Electronics, 13(13), 2604.

Banu, A. S., & Padmavathi, G. (2023). Hybrid Detection and Mitigation of DNS Protocol MITM Attack Based on Firefly Algorithm With Elliptical Curve Cryptography. Eai Endorsed Transactions on Pervasive Health and Technology, 9, e2. https://doi.org/10.4108/eetpht.v9i1.3177

Bella, K., Guezzaz, A., Benkirane, S., Azrour, M., Fouad, Y., Benyeogor, M. S., & Innab, N. (2024). An Efficient Intrusion Detection System for IoT Security Using CNN Decision Forest. Peerj Computer Science, 10, e2290. https://doi.org/10.7717/peerj-cs.2290

Cao, R., Tang, X., Cheng, S., Wu, Y., Tan, D., Liu, W., & Huang, M. (2024). A RS-BOLGBM Algorithm Based on LightGBM for Supercomputing Center Job Running Status Prediction. https://doi.org/10.21203/rs.3.rs-4120776/v1

Dini, P., Elhanashi, A., Begni, A., Saponara, S., Zheng, Q., & Gasmi, K. (2023). Overview on Intrusion Detection Systems Design Exploiting Machine Learning for Networking Cybersecurity. Applied Sciences, 13(13), 7507. https://doi.org/10.3390/app13137507

Diviya, M., Manivel, S., & Rani, D. G. N. (2025). An Optimized Phishing Detection Model Using Hybrid Feature Selection and a Fine-Tuned Narrow Neural Network With Dynamic Jaya Optimization to Overcome Cyberthreats. Engineering Research Express, 7(1), 015202. https://doi.org/10.1088/2631-8695/ada1a4

Gattu, H., Karimireddy, J., & Kanishka, G. (2025). DNS Under Siege: Ethical DNS Spoofing and Countermeasures. International Research Journal of Innovations in Engineering and Technology, 09(Special Issue), 250–254. https://doi.org/10.47001/irjiet/2025.inspire40

Guntoro, G., Lisnawita, L., & Costaner, L. (2024). Enhancing Cybersecurity: Innovative Hybrid Feature Selection for Intrusion Detection. https://doi.org/10.4108/eai.30-10-2023.2343092

Han, D., Li, H., & Fu, X. (2024). Reflective Distributed Denial of Service Detection: A Novel Model Utilizing Binary Particle Swarm Optimization—Simulated Annealing for Feature Selection and Gray Wolf Optimization-Optimized LightGBM Algorithm. Sensors, 24(19), 6179. https://doi.org/10.3390/s24196179

Kumar, R., Pan, C., Lin, Y., Shiue, Y., Chung, T.-S., & Janesha, U. G. S. (2025). Enhanced Multi-Model Deep Learning for Rapid and Precise Diagnosis of Pulmonary Diseases Using Chest X-Ray Imaging. Diagnostics, 15(3), 248. https://doi.org/10.3390/diagnostics15030248

Liu, J., Yang, D., Lian, M., & Li, M. (2021a). Research on Intrusion Detection Based on Particle Swarm Optimization in IoT. Ieee Access, 9, 38254–38268. https://doi.org/10.1109/access.2021.3063671

Liu, J., Yang, D., Lian, M., & Li, M. (2021b). Research on Intrusion Detection Based on Particle Swarm Optimization in IoT. Ieee Access, 9, 38254–38268. https://doi.org/10.1109/access.2021.3063671

Liu, J., Zeng, P., Guo, W., Wang, C., Geng, Y., Lang, N., & Yuan, H. (2021). Prediction of High?Risk Cytogenetic Status in Multiple Myeloma Based on Magnetic Resonance Imaging: Utility of Radiomics and Comparison of Machine Learning Methods. Journal of Magnetic Resonance Imaging, 54(4), 1303–1311. https://doi.org/10.1002/jmri.27637

Loureiro, A. A. B., & Stefani, R. (2024). Comparing the Performance of Machine Learning Models for Predicting the Compressive Strength of Concrete. https://doi.org/10.21203/rs.3.rs-4176429/v1

Meduri, K. (2025). IoT Network Security Anomaly Detection and Classification Using Deep Learning. Journal of Information Systems Engineering & Management, 10(6s), 181–191. https://doi.org/10.52783/jisem.v10i6s.712

Moon, Y. W., & Woo, H. (2025). Key Risk Factors of Generalized Anxiety Disorder in Adolescents: Machine Learning Study. Frontiers in Public Health, 12. https://doi.org/10.3389/fpubh.2024.1504739

Prakash, R. B., & K, P. R. (2024). Using Machine Learning to Detect Cyber Attacks. International Journal of Research Publication and Reviews, 5(2), 2793–2806. https://doi.org/10.55248/gengpi.5.0224.0555

Prayoga, I. G. P. A., Purbolaksono, M. D., & Adiwijaya, A. (2023). Sentiment Analysis on Indonesian Movie Review Using KNN Method With the Implementation of Chi-Square Feature Selection. Jurnal Media Informatika Budidarma, 7(1), 369. https://doi.org/10.30865/mib.v7i1.5522

Raufi, B., & Longo, L. (2024). Comparing ANOVA and PowerShap Feature Selection Methods via Shapley Additive Explanations of Models of Mental Workload Built With the Theta and Alpha EEG Band Ratios. Biomedinformatics, 4(1), 853–876. https://doi.org/10.3390/biomedinformatics4010048

Schaaf, K. v. d., Teki?nerdo?an, B., & Catal, C. (2021). A Feature?based Approach for Guiding the Selection of Internet of Things Cybersecurity Standards Using Text Mining. Concurrency and Computation Practice and Experience, 33(21). https://doi.org/10.1002/cpe.6385

Taherdoost, H. (2022). Understanding Cybersecurity Frameworks and Information Security Standards—A Review and Comprehensive Overview. Electronics, 11(14), 2181. https://doi.org/10.3390/electronics11142181

Vajrobol, V., Saxena, G. J., Pundir, A., Singh, S., Gupta, B. B., Gaurav, A., & Rahaman, M. (2024). Identify Spoofing Attacks in Internet of Things (IoT) Environments Using Machine Learning Algorithms. Journal of High Speed Networks, 31(1), 61–70. https://doi.org/10.1177/09266801241295886

Vitorino, J., Andrade, R., Praça, I., Sousa, O., & Maia, E. (2022). A Comparative Analysis of Machine Learning Techniques for IoT Intrusion Detection. 191–207. https://doi.org/10.1007/978-3-031-08147-7_13

Xie, B., Fei, L., Li, H., Wang, L., & Yang, A. (2023a). Enhanced Internet of Things Security Situation Assessment Model With Feature Optimization and Improved SSA-LightGBM. Mathematics, 11(16), 3617. https://doi.org/10.3390/math11163617

Xie, B., Fei, L., Li, H., Wang, L., & Yang, A. (2023b). Enhanced Internet of Things Security Situation Assessment Model With Feature Optimization and Improved SSA-LightGBM. Mathematics, 11(16), 3617. https://doi.org/10.3390/math11163617

Xu, J., Wang, Z., Zhang, X., Yu, J., Cui, X., Zhou, Y., & Zhao, Z. (2022). A Rice Security Risk Assessment Method Based on the Fusion of Multiple Machine Learning Models. Agriculture, 12(6), 815. https://doi.org/10.3390/agriculture12060815

Zebin, T., Rezvy, S., & Luo, Y. (2022). An Explainable AI-Based Intrusion Detection System for DNS Over HTTPS (DoH) Attacks. IEEE Transactions on Information Forensics and Security, 17, 2339–2349.

Zebin, T., Rezvy, S., & Luo, Y. (2025). MTL-DoHTA: Multi-Task Learning-Based DNS over HTTPS Traffic Analysis for Enhanced Network Security. Sensors, 25(4), 993.

Downloads

Published

2025-07-05

How to Cite

Budiansyah, A., Candra, R. A., Ilham, D. N., & Misbullah, A. (2025). Detection of DNS Spoofing Attacks on Campus Networks Using LightGBM with Hybrid Feature Selection (SelectKBest + SHAP). Brilliance: Research of Artificial Intelligence, 5(1), 298–304. https://doi.org/10.47709/brilliance.v5i1.5962