Detection of DNS Spoofing Attacks on Campus Networks Using LightGBM with Hybrid Feature Selection (SelectKBest + SHAP)
DOI:
https://doi.org/10.47709/brilliance.v5i1.5962Keywords:
DNS Spoofing, DNS over HTTPS, CIRA-CIC-DoHBrw-2020 dataset, Feature Selection, Elbow Method, Kneedle Method, LightGBM, Machine Learning, Network Security, CybersecurityAbstract
This study investigates the detection of Domain Name System over HTTPS (DoH) spoofing attacks utilizing the CIRA-CIC-DoHBrw-2020 dataset, which encompasses over 100,000 labeled DNS records categorized as either normal or malicious. Features such as packet timing, packet size, and TLS parameters are utilized for detection purposes. A systematic feature selection process is conducted utilizing the Elbow and Kneedle methods based on F-Score values derived from a built-in model evaluation. This method ensures that the top features are selected objectively and quantitatively, thereby enhancing the robustness of the model. The model is trained using the five most significant features, yielding exceptional performance metrics: a training time of just 0.5727 seconds, an inference time of 0.0157 seconds, and an inference latency of 0.0035 milliseconds per sample. Moreover, the model delivers an outstanding accuracy of 0.9995, an F1-Score of 0.9995, and an AUC-ROC of 1.0000, reflecting near-perfect detection capabilities. The classification report reveals a balanced distribution of precision, recall, and F1-Scores of 1.00 across both normal and malicious classes, based on a test sample of 14,974 entries. The Elbow plot visually confirms the optimal number of features utilized, while the SHAP beeswarm plot provides insights into how each selected feature contributes to the model’s predictions, facilitating interpretability. Additionally, the confusion matrix corroborates the model's reliability, showcasing that nearly all samples were accurately classified. The results demonstrate that the proposed methodology significantly enhances the effectiveness of DNS spoofing detection, offering a promising avenue for securing DNS over HTTPS communications.
References
Ajisafe, T. (2021). Developing Cardiometabolic Risk Classifiers for Youth Using Handgrip Strength, Anthropometrics, and Demographics: A Machine Learning Approach Leveraging National Health and Nutrition Examination Survey Data. https://doi.org/10.21203/rs.3.rs-488747/v1
Alawi, A. M. A., Shuaili, H. H. A., Al?Naamani, K., Naamani, Z. A., & Al?Busafi, S. A. (2024). A Machine Learning-Based Mortality Prediction Model for Patients With Chronic Hepatitis C Infection: An Exploratory Study. Journal of Clinical Medicine, 13(10), 2939. https://doi.org/10.3390/jcm13102939
Almusallam, A. (2021). Feature Engineering and Machine Learning Model Comparison for Malicious Activity Detection in the DNS-Over-HTTPS Protocol. IEEE Access, 9, 132159–132174.
Alshamrani, A. (2024). FSDC: Flow Samples and Dimensions Compression for Efficient Detection of DNS-over-HTTPS Tunnels. Electronics, 13(13), 2604.
Banu, A. S., & Padmavathi, G. (2023). Hybrid Detection and Mitigation of DNS Protocol MITM Attack Based on Firefly Algorithm With Elliptical Curve Cryptography. Eai Endorsed Transactions on Pervasive Health and Technology, 9, e2. https://doi.org/10.4108/eetpht.v9i1.3177
Bella, K., Guezzaz, A., Benkirane, S., Azrour, M., Fouad, Y., Benyeogor, M. S., & Innab, N. (2024). An Efficient Intrusion Detection System for IoT Security Using CNN Decision Forest. Peerj Computer Science, 10, e2290. https://doi.org/10.7717/peerj-cs.2290
Cao, R., Tang, X., Cheng, S., Wu, Y., Tan, D., Liu, W., & Huang, M. (2024). A RS-BOLGBM Algorithm Based on LightGBM for Supercomputing Center Job Running Status Prediction. https://doi.org/10.21203/rs.3.rs-4120776/v1
Dini, P., Elhanashi, A., Begni, A., Saponara, S., Zheng, Q., & Gasmi, K. (2023). Overview on Intrusion Detection Systems Design Exploiting Machine Learning for Networking Cybersecurity. Applied Sciences, 13(13), 7507. https://doi.org/10.3390/app13137507
Diviya, M., Manivel, S., & Rani, D. G. N. (2025). An Optimized Phishing Detection Model Using Hybrid Feature Selection and a Fine-Tuned Narrow Neural Network With Dynamic Jaya Optimization to Overcome Cyberthreats. Engineering Research Express, 7(1), 015202. https://doi.org/10.1088/2631-8695/ada1a4
Gattu, H., Karimireddy, J., & Kanishka, G. (2025). DNS Under Siege: Ethical DNS Spoofing and Countermeasures. International Research Journal of Innovations in Engineering and Technology, 09(Special Issue), 250–254. https://doi.org/10.47001/irjiet/2025.inspire40
Guntoro, G., Lisnawita, L., & Costaner, L. (2024). Enhancing Cybersecurity: Innovative Hybrid Feature Selection for Intrusion Detection. https://doi.org/10.4108/eai.30-10-2023.2343092
Han, D., Li, H., & Fu, X. (2024). Reflective Distributed Denial of Service Detection: A Novel Model Utilizing Binary Particle Swarm Optimization—Simulated Annealing for Feature Selection and Gray Wolf Optimization-Optimized LightGBM Algorithm. Sensors, 24(19), 6179. https://doi.org/10.3390/s24196179
Kumar, R., Pan, C., Lin, Y., Shiue, Y., Chung, T.-S., & Janesha, U. G. S. (2025). Enhanced Multi-Model Deep Learning for Rapid and Precise Diagnosis of Pulmonary Diseases Using Chest X-Ray Imaging. Diagnostics, 15(3), 248. https://doi.org/10.3390/diagnostics15030248
Liu, J., Yang, D., Lian, M., & Li, M. (2021a). Research on Intrusion Detection Based on Particle Swarm Optimization in IoT. Ieee Access, 9, 38254–38268. https://doi.org/10.1109/access.2021.3063671
Liu, J., Yang, D., Lian, M., & Li, M. (2021b). Research on Intrusion Detection Based on Particle Swarm Optimization in IoT. Ieee Access, 9, 38254–38268. https://doi.org/10.1109/access.2021.3063671
Liu, J., Zeng, P., Guo, W., Wang, C., Geng, Y., Lang, N., & Yuan, H. (2021). Prediction of High?Risk Cytogenetic Status in Multiple Myeloma Based on Magnetic Resonance Imaging: Utility of Radiomics and Comparison of Machine Learning Methods. Journal of Magnetic Resonance Imaging, 54(4), 1303–1311. https://doi.org/10.1002/jmri.27637
Loureiro, A. A. B., & Stefani, R. (2024). Comparing the Performance of Machine Learning Models for Predicting the Compressive Strength of Concrete. https://doi.org/10.21203/rs.3.rs-4176429/v1
Meduri, K. (2025). IoT Network Security Anomaly Detection and Classification Using Deep Learning. Journal of Information Systems Engineering & Management, 10(6s), 181–191. https://doi.org/10.52783/jisem.v10i6s.712
Moon, Y. W., & Woo, H. (2025). Key Risk Factors of Generalized Anxiety Disorder in Adolescents: Machine Learning Study. Frontiers in Public Health, 12. https://doi.org/10.3389/fpubh.2024.1504739
Prakash, R. B., & K, P. R. (2024). Using Machine Learning to Detect Cyber Attacks. International Journal of Research Publication and Reviews, 5(2), 2793–2806. https://doi.org/10.55248/gengpi.5.0224.0555
Prayoga, I. G. P. A., Purbolaksono, M. D., & Adiwijaya, A. (2023). Sentiment Analysis on Indonesian Movie Review Using KNN Method With the Implementation of Chi-Square Feature Selection. Jurnal Media Informatika Budidarma, 7(1), 369. https://doi.org/10.30865/mib.v7i1.5522
Raufi, B., & Longo, L. (2024). Comparing ANOVA and PowerShap Feature Selection Methods via Shapley Additive Explanations of Models of Mental Workload Built With the Theta and Alpha EEG Band Ratios. Biomedinformatics, 4(1), 853–876. https://doi.org/10.3390/biomedinformatics4010048
Schaaf, K. v. d., Teki?nerdo?an, B., & Catal, C. (2021). A Feature?based Approach for Guiding the Selection of Internet of Things Cybersecurity Standards Using Text Mining. Concurrency and Computation Practice and Experience, 33(21). https://doi.org/10.1002/cpe.6385
Taherdoost, H. (2022). Understanding Cybersecurity Frameworks and Information Security Standards—A Review and Comprehensive Overview. Electronics, 11(14), 2181. https://doi.org/10.3390/electronics11142181
Vajrobol, V., Saxena, G. J., Pundir, A., Singh, S., Gupta, B. B., Gaurav, A., & Rahaman, M. (2024). Identify Spoofing Attacks in Internet of Things (IoT) Environments Using Machine Learning Algorithms. Journal of High Speed Networks, 31(1), 61–70. https://doi.org/10.1177/09266801241295886
Vitorino, J., Andrade, R., Praça, I., Sousa, O., & Maia, E. (2022). A Comparative Analysis of Machine Learning Techniques for IoT Intrusion Detection. 191–207. https://doi.org/10.1007/978-3-031-08147-7_13
Xie, B., Fei, L., Li, H., Wang, L., & Yang, A. (2023a). Enhanced Internet of Things Security Situation Assessment Model With Feature Optimization and Improved SSA-LightGBM. Mathematics, 11(16), 3617. https://doi.org/10.3390/math11163617
Xie, B., Fei, L., Li, H., Wang, L., & Yang, A. (2023b). Enhanced Internet of Things Security Situation Assessment Model With Feature Optimization and Improved SSA-LightGBM. Mathematics, 11(16), 3617. https://doi.org/10.3390/math11163617
Xu, J., Wang, Z., Zhang, X., Yu, J., Cui, X., Zhou, Y., & Zhao, Z. (2022). A Rice Security Risk Assessment Method Based on the Fusion of Multiple Machine Learning Models. Agriculture, 12(6), 815. https://doi.org/10.3390/agriculture12060815
Zebin, T., Rezvy, S., & Luo, Y. (2022). An Explainable AI-Based Intrusion Detection System for DNS Over HTTPS (DoH) Attacks. IEEE Transactions on Information Forensics and Security, 17, 2339–2349.
Zebin, T., Rezvy, S., & Luo, Y. (2025). MTL-DoHTA: Multi-Task Learning-Based DNS over HTTPS Traffic Analysis for Enhanced Network Security. Sensors, 25(4), 993.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2025 Arie Budiansyah, Rudi Arif Candra, Dirja Nur Ilham, Alim Misbullah

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.















