Abstract
DNS-based data exfiltration represents a critical cybersecurity threat that exploits the ubiquity of DNS protocol communications to establish covert channels for unauthorized data transfer. This study presents a systematic comparative evaluation of eight lightweight machine learning classifiers for real-time DNS exfiltration detection, addressing critical gaps in adversarial robustness and practical deployment considerations. Using a dataset of 1,068,892 DNS query-response pairs (74.62% benign, 25.38% malicious), including malicious traffic captured from three exfiltration tools (iodine, dnsexfiltrator, and CobaltStrike) selected from a broader collection of nine tools, we evaluated Random Forest, Extra Trees, Gradient Boosting, Decision Tree, Logistic Regression, Linear SVM, Gaussian Naive Bayes, and Multi-layer Perceptron classifiers under dual configurations: complete feature sets (31 attributes) and adversarially-resilient configurations with timing-dependent and packet-size features removed. While tree-based ensemble methods achieved near-perfect performance metrics (99.99-100% accuracy), these results likely indicate overfitting to dataset-specific artifacts rather than genuine learning capability. Feature importance analysis revealed a heavy reliance on easily manipulated attributes such as TTL values (97.58% importance) and packet sizes, confirming that such models may memorize patterns rather than learn robust detection principles. In contrast, linear classifiers demonstrated more realistic performance (85-95% accuracy) with superior generalization capabilities under adversarial conditions. The findings challenge conventional performance-focused evaluation approaches, illustrating that models with moderate but stable accuracy may be better suited for production deployment against adaptive adversaries than classifiers reporting near-perfect metrics.
| Original language | English |
|---|---|
| Title of host publication | Proceedings of the 7th International Conference on Computer and Applications (ICCA 2025), December 22 - 24, 2025, Arab Open University, Bahrain |
| Editors | Jihad M. Alja'am, Najmah Taqi |
| Place of Publication | U.S. |
| Publisher | IEEE |
| Number of pages | 7 |
| ISBN (Electronic) | 9798331599539 |
| DOIs | |
| Publication status | Published - 2025 |
| Event | International Conference on Computer and Applications - Manama, Bahrain Duration: 22 Dec 2025 → 24 Dec 2025 Conference number: 7th |
Conference
| Conference | International Conference on Computer and Applications |
|---|---|
| Country/Territory | Bahrain |
| City | Manama |
| Period | 22/12/25 → 24/12/25 |
Keywords
- adversarial robustness
- anomaly detection
- cybersecurity
- DNS exfiltration
- machine learning
- network security
Fingerprint
Dive into the research topics of 'Flag the flow: AI-powered anomaly detection for data exfiltration in network traffic'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver