Skip to main navigation Skip to search Skip to main content

Flag the flow: AI-powered anomaly detection for data exfiltration in network traffic

  • Western Sydney University

Research output: Chapter in Book / Conference PaperConference Paperpeer-review

Abstract

DNS-based data exfiltration represents a critical cybersecurity threat that exploits the ubiquity of DNS protocol communications to establish covert channels for unauthorized data transfer. This study presents a systematic comparative evaluation of eight lightweight machine learning classifiers for real-time DNS exfiltration detection, addressing critical gaps in adversarial robustness and practical deployment considerations. Using a dataset of 1,068,892 DNS query-response pairs (74.62% benign, 25.38% malicious), including malicious traffic captured from three exfiltration tools (iodine, dnsexfiltrator, and CobaltStrike) selected from a broader collection of nine tools, we evaluated Random Forest, Extra Trees, Gradient Boosting, Decision Tree, Logistic Regression, Linear SVM, Gaussian Naive Bayes, and Multi-layer Perceptron classifiers under dual configurations: complete feature sets (31 attributes) and adversarially-resilient configurations with timing-dependent and packet-size features removed. While tree-based ensemble methods achieved near-perfect performance metrics (99.99-100% accuracy), these results likely indicate overfitting to dataset-specific artifacts rather than genuine learning capability. Feature importance analysis revealed a heavy reliance on easily manipulated attributes such as TTL values (97.58% importance) and packet sizes, confirming that such models may memorize patterns rather than learn robust detection principles. In contrast, linear classifiers demonstrated more realistic performance (85-95% accuracy) with superior generalization capabilities under adversarial conditions. The findings challenge conventional performance-focused evaluation approaches, illustrating that models with moderate but stable accuracy may be better suited for production deployment against adaptive adversaries than classifiers reporting near-perfect metrics.

Original languageEnglish
Title of host publicationProceedings of the 7th International Conference on Computer and Applications (ICCA 2025), December 22 - 24, 2025, Arab Open University, Bahrain
EditorsJihad M. Alja'am, Najmah Taqi
Place of PublicationU.S.
PublisherIEEE
Number of pages7
ISBN (Electronic)9798331599539
DOIs
Publication statusPublished - 2025
EventInternational Conference on Computer and Applications - Manama, Bahrain
Duration: 22 Dec 202524 Dec 2025
Conference number: 7th

Conference

ConferenceInternational Conference on Computer and Applications
Country/TerritoryBahrain
CityManama
Period22/12/2524/12/25

Keywords

  • adversarial robustness
  • anomaly detection
  • cybersecurity
  • DNS exfiltration
  • machine learning
  • network security

Fingerprint

Dive into the research topics of 'Flag the flow: AI-powered anomaly detection for data exfiltration in network traffic'. Together they form a unique fingerprint.

Cite this