{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,1]],"date-time":"2026-04-01T04:45:04Z","timestamp":1775018704549,"version":"3.50.1"},"reference-count":31,"publisher":"Pleiades Publishing Ltd","issue":"8","license":[{"start":{"date-parts":[[2025,12,1]],"date-time":"2025-12-01T00:00:00Z","timestamp":1764547200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,12,1]],"date-time":"2025-12-01T00:00:00Z","timestamp":1764547200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Program Comput Soft"],"published-print":{"date-parts":[[2025,12]]},"DOI":"10.1134\/s0361768825700537","type":"journal-article","created":{"date-parts":[[2026,2,27]],"date-time":"2026-02-27T10:50:35Z","timestamp":1772189435000},"page":"727-751","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["DNS Tunneling Detection Using Methods of Machine Learning"],"prefix":"10.1134","volume":"51","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8117-9142","authenticated-orcid":false,"given":"M.","family":"Lapina","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-6276-8051","authenticated-orcid":false,"given":"K.","family":"Gediev","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7066-0061","authenticated-orcid":false,"given":"M.","family":"Babenko","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5029-5212","authenticated-orcid":false,"given":"A.","family":"Tchernykh","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5607-2749","authenticated-orcid":false,"given":"A. Yu.","family":"Drozdov","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"137","published-online":{"date-parts":[[2026,2,27]]},"reference":[{"key":"3985_CR1","doi-asserted-by":"publisher","unstructured":"Mockapetris, P.V., Domain names: Concepts and facilities, RFC 882, RFC Editor, 1983. https:\/\/doi.org\/10.17487\/rfc0882","DOI":"10.17487\/rfc0882"},{"key":"3985_CR2","doi-asserted-by":"publisher","unstructured":"Kozlenko, M. and Tkachuk, V., Deep learning based detection of DNS spoofing attack. https:\/\/doi.org\/10.5281\/zenodo.4091018","DOI":"10.5281\/zenodo.4091018"},{"key":"3985_CR3","unstructured":"Kaminsky, D., Black Ops 2008: It\u2019s the end of the cache as we know it, Black Hat USA."},{"key":"3985_CR4","unstructured":"What is a DNS DDoS attack?. https:\/\/www.akamai.com\/glossary\/what-is-a-dns-ddos-attack. Cited April 5, 2025."},{"key":"3985_CR5","unstructured":"Born, K. and Gustafson, D., Detecting DNS tunnels using character frequency analysis, Proceedings of the Ninth Annual Security Conference, 2010."},{"key":"3985_CR6","unstructured":"What is a command and control attack?. \nhttps:\/\/www.paloaltonetworks.com\/cyberpedia\/command-and-control-explained. Cited April 5, 2025."},{"key":"3985_CR7","unstructured":"Schechter, J., DNS and the challenge of advanced persistent threats. https:\/\/bluecatnetworks.com\/blog\/dns-challenge-advanced-persistent-threats\/. Cited April 5, 2025."},{"key":"3985_CR8","unstructured":"Diouf, M., Securing the Internet of Things: Combating DNS tunnelling threats, 2025. https:\/\/www.cyberpass.com\/blog\/dns-tunneling. Cited April 5, 2025."},{"key":"3985_CR9","doi-asserted-by":"publisher","unstructured":"Siva Kumar, R.Sh., Nystr\u00f6m, M., Lambert, J., Marshall, A., Goertzel, M., Comissoneru, A., Swann, M., and Xia, Sh., Adversarial machine learning-industry perspectives, IEEE Security and Privacy Workshops (SPW), San Francisco, CA, IEEE, 2020, pp. 69\u201375. https:\/\/doi.org\/10.1109\/SPW50608.2020.00028","DOI":"10.1109\/SPW50608.2020.00028"},{"key":"3985_CR10","doi-asserted-by":"publisher","unstructured":"Papernot, N., McDaniel, P., Jha, S., Fredrikson, M., Celik, Z.B., and Swami, A., The limitations of deep learning in adversarial settings, IEEE European Symposium on Security and Privacy (EuroS amp;P), Saarbruecken, Germany, 2016, IEEE, 2016, pp. 372\u2013387. https:\/\/doi.org\/10.1109\/eurosp.2016.36","DOI":"10.1109\/eurosp.2016.36"},{"key":"3985_CR11","doi-asserted-by":"publisher","first-page":"1865","DOI":"10.1007\/s10207-023-00723-w","volume":"22","author":"K. \u017di\u017ea","year":"2023","unstructured":"\u017di\u017ea, K., Tadi\u0107, P., and Vuletic, P., DNS exfiltration detection in the presence of adversarial attacks and modified exfiltrator behaviour, Int. J. Inf. Secur., 2023, vol. 22, pp. 1865\u20131880. https:\/\/doi.org\/10.1007\/s10207-023-00723-w","journal-title":"Int. J. Inf. Secur."},{"key":"3985_CR12","doi-asserted-by":"publisher","unstructured":"Carlini, N. and Wagner, D., Towards evaluating the robustness of neural networks, 2017 IEEE Symposium on Security and Privacy (SP), San Jose, CA, IEEE, 2017, pp. 39\u201357. https:\/\/doi.org\/10.1109\/sp.2017.49","DOI":"10.1109\/sp.2017.49"},{"key":"3985_CR13","doi-asserted-by":"publisher","unstructured":"Sommer, R. and Paxson, V., Outside the closed world: On using machine learning for network intrusion detection, IEEE Symposium on Security and Privacy, Oakland, CA, 2010, IEEE, 2010, pp. 305\u2013316. https:\/\/doi.org\/10.1109\/sp.2010.25","DOI":"10.1109\/sp.2010.25"},{"key":"3985_CR14","doi-asserted-by":"publisher","unstructured":"Yu, B., Olumofin, F., Smith, L., and Threefoot, M., Behavior analysis based DNS tunneling detection and classification with big data technologies, Proceedings of the International Conference on Internet of Things and Big Data, SCITEPRESS - Science and and Technology Publications, 2016, vol. 1, pp. 284\u2013290. https:\/\/doi.org\/10.5220\/0005795002840290","DOI":"10.5220\/0005795002840290"},{"key":"3985_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-67380-6_26","volume-title":"DNS tunneling detection techniques\u2014Classification, and theoretical comparison in case of a real APT campaign, Internet of Things, Smart Spaces, and Next Generation Networks and Systems","author":"V. Nuojua","year":"2017","unstructured":"Nuojua, V., David, G., and H\u00e4m\u00e4l\u00e4inen, T., DNS tunneling detection techniques\u2014Classification, and theoretical comparison in case of a real APT campaign, Internet of Things, Smart Spaces, and Next Generation Networks and Systems, Galinina, O., Andreev, S., Balandin, S., and Koucheryavy, Y., Eds., Lecture Notes in Computer Science, vol. 10531, Cham: Springer, 2017, pp. 280\u2013291. https:\/\/doi.org\/10.1007\/978-3-319-67380-6_26"},{"key":"3985_CR16","doi-asserted-by":"publisher","unstructured":"Almusawi, A. and Amintoosi, H., DNS Tunneling Detection Method Based on Multilabel Support Vector Machine, Security and Communication Networks, 2018, vol. 2018, p. 6137098. https:\/\/doi.org\/10.1155\/2018\/6137098","DOI":"10.1155\/2018\/6137098"},{"key":"3985_CR17","doi-asserted-by":"publisher","unstructured":"Preston, R., DNS tunneling detection with supervised learning, 2019 IEEE International Symposium on Technologies for Homeland Security (HST), Woburn, MA, IEEE, 2019, pp. 1\u20136. https:\/\/doi.org\/10.1109\/HST47167.2019.9032913","DOI":"10.1109\/HST47167.2019.9032913"},{"key":"3985_CR18","doi-asserted-by":"publisher","first-page":"265","DOI":"10.1109\/tnsm.2019.2940735","volume":"17","author":"J. Ahmed","year":"2020","unstructured":"Ahmed, J., Habibi Gharakheili, H., Raza, Q., Russell, C., and Sivaraman, V., Monitoring enterprise DNS queries for detecting data exfiltration from internal hosts, IEEE Trans. Network Service Manage., 2020, vol. 17, no. 1, pp. 265\u2013279. https:\/\/doi.org\/10.1109\/tnsm.2019.2940735","journal-title":"IEEE Trans. Network Service Manage."},{"key":"3985_CR19","first-page":"241","volume":"10","author":"G. Sakarkar","year":"2021","unstructured":"Sakarkar, G., Kolekar, M.K.H., Paithankar, K., Patil, G., Dutta, P., Chaturvedi, R., and Kumar, S., Advance approach for detection of dns tunneling attack from network packets using deep learning algorithms, Adv. Distrib. Comput. Artif. Intell. J., 2021, vol. 10, pp. 241\u2013266.","journal-title":"Adv. Distrib. Comput. Artif. Intell. J."},{"key":"3985_CR20","doi-asserted-by":"publisher","first-page":"39","DOI":"10.4316\/aece.2021.03005","volume":"21","author":"M.A. Altuncu","year":"2021","unstructured":"Altuncu, M.A., Gulagiz, F.K., Ozcan, H., Bayir, O.F., Gezgin, A., Niyazov, A., Cavuslu, M.A., and Sahin, S., Deep learning based DNS tunneling detection and blocking system, Adv. Electr. Comput. Eng., 2021, vol.\u00a021, no. 3, pp. 39\u201348. https:\/\/doi.org\/10.4316\/aece.2021.03005","journal-title":"Adv. Electr. Comput. Eng."},{"key":"3985_CR21","doi-asserted-by":"publisher","unstructured":"D\u2019Angelo, G., Castiglione, A., and Palmieri, F., DNS tunnels detection via DNS-images, Inf. Process. Manage., 2022, vol. 59, no. 3, p. 102930. https:\/\/doi.org\/10.1016\/j.ipm.2022.102930","DOI":"10.1016\/j.ipm.2022.102930"},{"key":"3985_CR22","doi-asserted-by":"publisher","first-page":"153","DOI":"10.1109\/tdsc.2023.3247585","volume":"21","author":"H. Yan","year":"2023","unstructured":"Yan, H., Li, X., Zhang, W., Wang, R., Li, H., Zhao, X., Li, F., and Lin, X., Automatic evasion of machine learning-based network intrusion detection systems, IEEE Trans. Dependable Secure Comput., 2023, vol. 21, no. 1, pp. 153\u2013167. https:\/\/doi.org\/10.1109\/tdsc.2023.3247585","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"3985_CR23","doi-asserted-by":"publisher","unstructured":"Savi\u0107, I., Yan, H., Lin, X., and Gillis, D., Adversarial example attacks and defenses in DNS data exfiltration, Emerging Information Security and Applications. EISA 2023, Shao, J., Katsikas, S.K., and Meng, W., Eds., Communications in Computer and Information Science, vol. 2004, Singapore: Springer, 2024, pp. 147\u2013163. https:\/\/doi.org\/10.1007\/978-981-99-9614-8_10","DOI":"10.1007\/978-981-99-9614-8_10"},{"key":"3985_CR24","unstructured":"Vaccari, I., Carlevaro, A., Narteni, S., Cambiaso, E., and Mongelli, M., Adversarial machine learning dataset, 2025. https:\/\/www.kaggle.com\/datasets\/cnrieiit\/adversarial-machine-learning-dataset. Cited April 9, 2025."},{"key":"3985_CR25","doi-asserted-by":"publisher","first-page":"120","DOI":"10.1049\/iet-cps.2018.5055","volume":"4","author":"M. Mongelli","year":"2018","unstructured":"Mongelli, M., Ferrari, E., Muselli, M., and Fermi, A., Performance validation of vehicle platooning through intelligible analytics, IET Cyber-Phys. \n               Syst.: Theory Appl., 2018, vol. 4, no. 2, pp. 120\u2013127. https:\/\/doi.org\/10.1049\/iet-cps.2018.5055","journal-title":"Syst.: Theory Appl."},{"key":"3985_CR26","doi-asserted-by":"publisher","unstructured":"Saxena, A., Goebel, K., Simon, D., and Eklund, N., Damage propagation modeling for aircraft engine run-to-failure simulation, 2008 International Conference on Prognostics and Health Management, Denver, CO, IEEE, 2008, pp. 1\u20139. https:\/\/doi.org\/10.1109\/phm.2008.4711414","DOI":"10.1109\/phm.2008.4711414"},{"key":"3985_CR27","doi-asserted-by":"publisher","DOI":"10.1109\/ivmem57067.2022.9983955","volume-title":"Static analysis methods for memory leak detection: A survey, 2022 Ivannikov Memorial Workshop (IVMEM)","author":"H. Aslanyan","year":"2022","unstructured":"Aslanyan, H., Gevorgyan, Zh., Mkoyan, R., Movsisyan, H., Sahakyan, V., and Sargsyan, S., Static analysis methods for memory leak detection: A survey, 2022 Ivannikov Memorial Workshop (IVMEM), IEEE, 2022, pp. 1\u20136. https:\/\/doi.org\/10.1109\/ivmem57067.2022.9983955"},{"key":"3985_CR28","doi-asserted-by":"publisher","unstructured":"Sargsyan, S., Kurmangaleev, Sh., Hakobyan, J., Mehrabyan, M., Asryan, S., and Movsisyan, H., Directed fuzzing based on program dynamic instrumentation, 2019 International Conference on Engineering Technologies and Computer Science (EnT), IEEE, 2019, pp. 30\u201333. https:\/\/doi.org\/10.1109\/ent.2019.00011","DOI":"10.1109\/ent.2019.00011"},{"key":"3985_CR29","doi-asserted-by":"publisher","DOI":"10.1109\/csitechnol.2015.7358259","volume-title":"LLVM-based code clone detection framework, 2015 Computer Science and Information Technologies (CSIT)","author":"A. Avetisyan","year":"2015","unstructured":"Avetisyan, A., Kurmangaleev, Sh., Sargsyan, S., Arutunian, M., and Belevantsev, A., LLVM-based code clone detection framework, 2015 Computer Science and Information Technologies (CSIT), IEEE, 2015, pp. 100\u2013104. https:\/\/doi.org\/10.1109\/csitechnol.2015.7358259"},{"key":"3985_CR30","doi-asserted-by":"publisher","DOI":"10.1109\/ispras57371.2022.10076849","volume-title":"Improving fuzzing efficiency based on extracted constant values, 2022 Ivannikov Ispras Open Conference (ISPRAS)","author":"S. Sargsyan","year":"2022","unstructured":"Sargsyan, S., Hakobyan, J., Nersisyan, L., Sargsyan, K., and Melkonyan, V., Improving fuzzing efficiency based on extracted constant values, 2022 Ivannikov Ispras Open Conference (ISPRAS), IEEE, 2022, pp. 81\u201385. https:\/\/doi.org\/10.1109\/ispras57371.2022.10076849"},{"key":"3985_CR31","doi-asserted-by":"publisher","DOI":"10.1109\/ivmem57067.2022.9983953","volume-title":"Advanced grammar-based fuzzing, 2022 Ivannikov Memorial Workshop (IVMEM)","author":"S. Sargsyan","year":"2022","unstructured":"Sargsyan, S., Hakobyan, J., Mehrabyan, M., Mkoyan, R., Sahakyan, V., Melkonyan, V., Arutunian, M., Fahradyan, A., and Avetisyan, A., Advanced grammar-based fuzzing, 2022 Ivannikov Memorial Workshop (IVMEM), IEEE, 2022, pp. 61\u201364. https:\/\/doi.org\/10.1109\/ivmem57067.2022.9983953"}],"container-title":["Programming and Computer Software"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1134\/S0361768825700537.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1134\/S0361768825700537","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1134\/S0361768825700537.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,1]],"date-time":"2026-04-01T02:55:12Z","timestamp":1775012112000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1134\/S0361768825700537"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,12]]},"references-count":31,"journal-issue":{"issue":"8","published-print":{"date-parts":[[2025,12]]}},"alternative-id":["3985"],"URL":"https:\/\/doi.org\/10.1134\/s0361768825700537","relation":{},"ISSN":["0361-7688","1608-3261"],"issn-type":[{"value":"0361-7688","type":"print"},{"value":"1608-3261","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,12]]},"assertion":[{"value":"17 August 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"27 August 2025","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"27 August 2025","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"27 February 2026","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"The authors of this work declare that they have no conflicts of interest.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"CONFLICT OF INTEREST"}}]}}