An Intelligent System for DNS Spoofing Detection in Network Traffic

Authors

  • Arunbalaji M Department of Computer Science and Engineering, Panimalar Engineering College, Chennai, India.
  • Adil A Department of Computer Science and Engineering, Panimalar Engineering College, Chennai, India.
  • Anitha Moses V Department of Computer Science and Engineering, Panimalar Engineering College, Chennai, India.

Keywords:

DNS Spoofing, Network Security, Machine Learning, Cybersecurity, Real-Time Detection, Anomaly Detection

Abstract

DNS spoofing is a significant cybersecurity threat that compromises the integrity of domain name resolution and enables attacks such as phishing, identity theft, and data breaches. Traditional rule-based detection systems lack adaptability and fail to detect sophisticated and evolving spoofing attacks in real time. This paper proposes an intelligent AI-driven system for detecting DNS spoofing in live network traffic. The system integrates real-time packet capture, multi-level feature extraction, and supervised machine learning models such as Random Forest and XGBoost for classification. Key features including Time-To-Live (TTL), response time, domain entropy, and network attributes are analyzed to identify anomalies. The system employs automated decision logic to block or allow traffic based on spoofing probability. Experimental evaluation demonstrates a detection accuracy of 94.6% with reduced false positives and an average response time of 320 ms. The proposed system is lightweight, scalable, and suitable for deployment in enterprise and campus networks.

Downloads

Download data is not yet available.

References

P. Mockapetris, “Domain names—Concepts and facilities,” RFC 1034, 1987.

R. Arends et al., “DNS Security Introduction and Requirements,” RFC 4033, 2005.

S. Almusawi, R. Al-Shaikhli, and W. Al-Mashaqbeh, “Machine Learning Approaches for DNS Anomaly Detection: A Survey,” IEEE Access, vol. 10, pp. 105432–105447, 2022.

H. Chen et al., “DNS Spoofing Detection Based on Random Forest and Flow Features,” IEEE Transactions on Network and Service Management, vol. 19, no. 3, pp. 2652–2663, 2022.

X. Li, Y. Wang, and Z. Zhang, “An Adaptive Detection Framework for DNS Cache Poisoning Using XGBoost,” Computers & Security, vol. 121, 2023.

J. Lee and K. Lee, “Detection of DNS Spoofing Attacks Using Deep Learning Models,” Sensors, vol. 22, no. 4, 2022.

F. Iqbal and M. K. Khan, “An AI-Driven Architecture for DNS Attack Detection and Mitigation,” IEEE Access, vol. 11, pp. 45894–45907, 2023

M. Ahmad et al., “Lightweight DNS Spoofing Detection Model Using Supervised Learning,” Journal of Network and Computer Applications, vol. 235, 2025.

S. Gupta and R. Singh, “Deep Learning for DNS Threat Detection in Cloud Environments,” IEEE Transactions on Information Forensics and Security, 2024.

Y. Zhao et al., “A CNN-LSTM Hybrid Approach for Real-Time DNS Anomaly Detection,” Expert Systems with Applications, vol. 238, 2025.

P. Das et al., “Explainable AI for DNS Security: SHAP-Based Feature Interpretation,” IEEE Internet of Things Journal, 2024.

[A. Dhingra and V. Jain, “Machine Learning for DNS Threat Detection: Challenges and Opportunities,” IEEE Communications Surveys & Tutorials, 2023.

K. Liu et al., “Feature Engineering for DNS Anomaly Detection Using Statistical Analysis,” Computers & Security, 2024.

A. Singh and S. Tiwari, “A Real-Time DNS Monitoring System Using MQTT and RESTful APIs,” International Journal of Computer Networks, 2024.

Z. Huang et al., “Performance Evaluation of AI Models for DNS Spoofing Detection,” IEEE Sensors Journal, 2023.

Downloads

Published

2026-03-15

Issue

Section

Articles

How to Cite

Arunbalaji M, Adil A, and Anitha Moses V. 2026. “An Intelligent System for DNS Spoofing Detection in Network Traffic ”. International Journal of Applied Smart Interdisciplinary Technologies (IJASIT) 1 (1): 28-35. https://ijasit.org/index.php/home/article/view/6.

Most read articles by the same author(s)

Similar Articles

11-20 of 26

You may also start an advanced similarity search for this article.