TY - GEN
T1 - A Unified Knowledge-Driven Framework for Encrypted DNS Threat Awareness
AU - Bao, Qiming
AU - Tang, Hao
AU - Yan, Jiawei
AU - He, Hui
AU - Zhang, Weizhe
AU - Yang, Hongwei
N1 - Publisher Copyright:
© 2025 IEEE.
PY - 2025
Y1 - 2025
N2 - The rapid adoption of encrypted Domain Name System (DNS) protocols has brought about a critical dilemma: while significantly enhancing user privacy, it has also blurred network visibility, creating blind spots for traffic monitoring and enabling malicious actors to evade detection and launch sophisticated attacks. Existing research often focuses on single directions, such as traffic classification or anomaly detection, lacking a unified framework that incorporates accurate identification, structured modeling, and intelligent reasoning. To address this issue, we propose a novel unified framework that integrates deep learning, knowledge graphs, and large language models. Our Long Short-Term Memory (LSTM)-based classifier achieved an F1 score of 98.9% in identifying encrypted DNS traffic. The dynamically constructed knowledge graph in Neo4j captures complex threat relationships and temporal evolution. Finally, we leverage the DeepSeek Large Language Model (LLM) for predictive reasoning and generation of mitigation strategies. Experimental results validate the effectiveness of our framework in accurate traffic classification, threat association, and proactive defense. This work provides a pioneering and scalable solution to the growing challenges of encrypted DNS security.
AB - The rapid adoption of encrypted Domain Name System (DNS) protocols has brought about a critical dilemma: while significantly enhancing user privacy, it has also blurred network visibility, creating blind spots for traffic monitoring and enabling malicious actors to evade detection and launch sophisticated attacks. Existing research often focuses on single directions, such as traffic classification or anomaly detection, lacking a unified framework that incorporates accurate identification, structured modeling, and intelligent reasoning. To address this issue, we propose a novel unified framework that integrates deep learning, knowledge graphs, and large language models. Our Long Short-Term Memory (LSTM)-based classifier achieved an F1 score of 98.9% in identifying encrypted DNS traffic. The dynamically constructed knowledge graph in Neo4j captures complex threat relationships and temporal evolution. Finally, we leverage the DeepSeek Large Language Model (LLM) for predictive reasoning and generation of mitigation strategies. Experimental results validate the effectiveness of our framework in accurate traffic classification, threat association, and proactive defense. This work provides a pioneering and scalable solution to the growing challenges of encrypted DNS security.
KW - encrypted DNS
KW - knowledge graph
KW - large model inference
KW - threat awareness
KW - traffic classification
UR - https://www.scopus.com/pages/publications/105032678077
U2 - 10.1109/MSN69125.2025.00045
DO - 10.1109/MSN69125.2025.00045
M3 - 会议稿件
AN - SCOPUS:105032678077
T3 - Proceedings - 2025 21st International Conference on Mobility, Sensing and Networking, MSN 2025
SP - 286
EP - 293
BT - Proceedings - 2025 21st International Conference on Mobility, Sensing and Networking, MSN 2025
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 21st IEEE International Conference on Mobility, Sensing and Networking, MSN 2025
Y2 - 3 December 2025 through 6 December 2025
ER -