An Intelligent System for DNS Spoofing Detection in Network Traffic
Keywords:
DNS Spoofing, Network Security, Machine Learning, Cybersecurity, Real-Time Detection, Anomaly DetectionAbstract
DNS spoofing is a significant cybersecurity threat that compromises the integrity of domain name resolution and enables attacks such as phishing, identity theft, and data breaches. Traditional rule-based detection systems lack adaptability and fail to detect sophisticated and evolving spoofing attacks in real time. This paper proposes an intelligent AI-driven system for detecting DNS spoofing in live network traffic. The system integrates real-time packet capture, multi-level feature extraction, and supervised machine learning models such as Random Forest and XGBoost for classification. Key features including Time-To-Live (TTL), response time, domain entropy, and network attributes are analyzed to identify anomalies. The system employs automated decision logic to block or allow traffic based on spoofing probability. Experimental evaluation demonstrates a detection accuracy of 94.6% with reduced false positives and an average response time of 320 ms. The proposed system is lightweight, scalable, and suitable for deployment in enterprise and campus networks.
Downloads
References
P. Mockapetris, “Domain names—Concepts and facilities,” RFC 1034, 1987.
R. Arends et al., “DNS Security Introduction and Requirements,” RFC 4033, 2005.
S. Almusawi, R. Al-Shaikhli, and W. Al-Mashaqbeh, “Machine Learning Approaches for DNS Anomaly Detection: A Survey,” IEEE Access, vol. 10, pp. 105432–105447, 2022.
H. Chen et al., “DNS Spoofing Detection Based on Random Forest and Flow Features,” IEEE Transactions on Network and Service Management, vol. 19, no. 3, pp. 2652–2663, 2022.
X. Li, Y. Wang, and Z. Zhang, “An Adaptive Detection Framework for DNS Cache Poisoning Using XGBoost,” Computers & Security, vol. 121, 2023.
J. Lee and K. Lee, “Detection of DNS Spoofing Attacks Using Deep Learning Models,” Sensors, vol. 22, no. 4, 2022.
F. Iqbal and M. K. Khan, “An AI-Driven Architecture for DNS Attack Detection and Mitigation,” IEEE Access, vol. 11, pp. 45894–45907, 2023
M. Ahmad et al., “Lightweight DNS Spoofing Detection Model Using Supervised Learning,” Journal of Network and Computer Applications, vol. 235, 2025.
S. Gupta and R. Singh, “Deep Learning for DNS Threat Detection in Cloud Environments,” IEEE Transactions on Information Forensics and Security, 2024.
Y. Zhao et al., “A CNN-LSTM Hybrid Approach for Real-Time DNS Anomaly Detection,” Expert Systems with Applications, vol. 238, 2025.
P. Das et al., “Explainable AI for DNS Security: SHAP-Based Feature Interpretation,” IEEE Internet of Things Journal, 2024.
[A. Dhingra and V. Jain, “Machine Learning for DNS Threat Detection: Challenges and Opportunities,” IEEE Communications Surveys & Tutorials, 2023.
K. Liu et al., “Feature Engineering for DNS Anomaly Detection Using Statistical Analysis,” Computers & Security, 2024.
A. Singh and S. Tiwari, “A Real-Time DNS Monitoring System Using MQTT and RESTful APIs,” International Journal of Computer Networks, 2024.
Z. Huang et al., “Performance Evaluation of AI Models for DNS Spoofing Detection,” IEEE Sensors Journal, 2023.
Downloads
Published
Issue
Section
License

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.


