{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,10]],"date-time":"2026-04-10T16:06:14Z","timestamp":1775837174038,"version":"3.50.1"},"reference-count":24,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2022]]},"DOI":"10.1109\/tifs.2022.3183390","type":"journal-article","created":{"date-parts":[[2022,6,15]],"date-time":"2022-06-15T20:02:05Z","timestamp":1655323325000},"page":"2339-2349","source":"Crossref","is-referenced-by-count":135,"title":["An Explainable AI-Based Intrusion Detection System for DNS Over HTTPS (DoH) Attacks"],"prefix":"10.1109","volume":"17","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0437-0570","authenticated-orcid":false,"given":"Tahmina","family":"Zebin","sequence":"first","affiliation":[{"name":"School of Computing Science, University of East Anglia, Norwich, U.K"}]},{"given":"Shahadate","family":"Rezvy","sequence":"additional","affiliation":[{"name":"Department of Computer Science, School of Science, Technology and Health, York St John University, York, U.K"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9812-5543","authenticated-orcid":false,"given":"Yuan","family":"Luo","sequence":"additional","affiliation":[{"name":"Faculty of Science and Technology, Middlesex University London, London, U.K"}]}],"member":"263","reference":[{"key":"ref1","volume-title":"2021 Global DNS Threat Report","author":"Fouchereau","year":"2021"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/3407023.3409192"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2021.108322"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/ISCC.2013.6755060"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1155\/2019\/4612474"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2924633"},{"key":"ref7","article-title":"Detection of DoH tunnelling: Comparing supervised with unsupervised learning","author":"Vries","year":"2021"},{"key":"ref8","volume-title":"CIRA-CIC-DOHBRW-2020 Dataset","year":"2020"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/HST47167.2019.9032913"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.12691\/jcsa-8-2-2"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-16-3728-5_43"},{"key":"ref12","first-page":"65","article-title":"Analysis and investigation of malicious DNS queries using CIRA-CIC-DoHBrw-2020 dataset","volume":"2","author":"Jafar","year":"2021","journal-title":"Manchester J. Artif. Intell. Appl. Sci."},{"key":"ref13","first-page":"4768","article-title":"A unified approach to interpreting model predictions","volume-title":"Proc. 31st Int. Conf. neural Inf. Process. Syst.","author":"Lundberg"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/DASC-PICom-CBDCom-CyberSciTech49142.2020.00026"},{"key":"ref15","volume-title":"Data Mining: Practical Machine Learning Tools and Techniques","author":"Witten","year":"2016"},{"issue":"1","key":"ref16","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1023\/A:1010933404324","article-title":"Random forests","volume":"45","author":"Breiman","year":"2001","journal-title":"Mach. Learn."},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-16239-8_8"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.2478\/jos-2014-0005"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-05318-5_6"},{"issue":"1","key":"ref20","first-page":"127","article-title":"Combining multiple classifiers: Diversify with boosting and combining by stacking","volume":"7","author":"Hatami","year":"2007","journal-title":"Int. J. Comput. Sci. Netw. Secur."},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.21105\/joss.00638"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/ICAIIC54071.2022.9722641"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CISS.2019.8693059"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3113294"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10206\/9652463\/09796558.pdf?arnumber=9796558","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,2,1]],"date-time":"2024-02-01T03:37:16Z","timestamp":1706758636000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9796558\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"references-count":24,"URL":"https:\/\/doi.org\/10.1109\/tifs.2022.3183390","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022]]}}}