{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,29]],"date-time":"2026-07-29T17:02:54Z","timestamp":1785344574053,"version":"3.55.0"},"reference-count":33,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2025,12,18]],"date-time":"2025-12-18T00:00:00Z","timestamp":1766016000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0"},{"start":{"date-parts":[[2025,12,18]],"date-time":"2025-12-18T00:00:00Z","timestamp":1766016000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["EURASIP J. on Info. Security"],"DOI":"10.1186\/s13635-025-00215-5","type":"journal-article","created":{"date-parts":[[2025,12,18]],"date-time":"2025-12-18T08:34:20Z","timestamp":1766046860000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":16,"title":["Neuromorphic quantum adversarial learning (NQAL): a bio-inspired paradigm for DNS over HTTPS threat detection"],"prefix":"10.1186","volume":"2025","author":[{"given":"Basharat","family":"Ali","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Guihai","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,12,18]]},"reference":[{"key":"215_CR1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cosrev.2022.100469","volume":"45","author":"O Van Der Toorn","year":"2022","unstructured":"O. Van Der Toorn, M. M\u00fcller, S. Dickinson, C. Hesselman, A. Sperotto, R. van Rijswijk-Deij, Addressing the challenges of modern dns a comprehensive tutorial. Comput. Sci. Rev. 45, 100,469 (2022)","journal-title":"Comput. Sci. Rev."},{"key":"215_CR2","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2022.108919","volume":"209","author":"M Zhan","year":"2022","unstructured":"M. Zhan, Y. Li, G. Yu, B. Li, W. Wang, Detecting dns over https based data exfiltration. Comput. Netw. 209, 108,919 (2022)","journal-title":"Comput. Netw."},{"issue":"8","key":"215_CR3","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3547331","volume":"55","author":"M Lyu","year":"2022","unstructured":"M. Lyu, H.H. Gharakheili, V. Sivaraman, A survey on dns encryption: current development, malware misuse, and inference techniques. ACM Comput. Surv. 55(8), 1\u201328 (2022)","journal-title":"ACM Comput. Surv."},{"issue":"2","key":"215_CR4","doi-asserted-by":"publisher","first-page":"44","DOI":"10.1145\/3544912.3544918","volume":"52","author":"M Kosek","year":"2022","unstructured":"M. Kosek, T.V. Doan, S. Huber, V. Bajpai, Measuring DNS over TCP in the era of increasing DNS response sizes: a view from the edge. ACM SIGCOMM Comput. Commun. Rev. 52(2), 44\u201355 (2022)","journal-title":"ACM SIGCOMM Comput. Commun. Rev."},{"key":"215_CR5","doi-asserted-by":"crossref","unstructured":"R.\u00a0Houser, S.\u00a0Hao, C.\u00a0Cotton, H.\u00a0Wang, in 2022 52nd Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN), A comprehensive, longitudinal study of government dns deployment at global scale (IEEE, 2022), pp. 193\u2013204","DOI":"10.1109\/DSN53405.2022.00030"},{"key":"215_CR6","doi-asserted-by":"crossref","unstructured":"R.\u00a0Chhabra, P.\u00a0Murley, D.\u00a0Kumar, M.\u00a0Bailey, G.\u00a0Wang, in Proceedings of the 21st ACM Internet Measurement Conference, Measuring dns-over-https performance around the world (2021), pp. 351\u2013365","DOI":"10.1145\/3487552.3487849"},{"key":"215_CR7","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2024.110452","volume":"247","author":"K Jerabek","year":"2024","unstructured":"K. Jerabek, K. Hynek, O. Rysavy, Comparative analysis of DNS over HTTPS detectors. Comput. Netw. 247, 110,452 (2024)","journal-title":"Comput. Netw."},{"issue":"3","key":"215_CR8","doi-asserted-by":"publisher","first-page":"1369","DOI":"10.1109\/TNET.2022.3215507","volume":"31","author":"P Lin","year":"2022","unstructured":"P. Lin, K. Ye, Y. Hu, Y. Lin, C.Z. Xu, A novel multimodal deep learning framework for encrypted traffic classification. IEEE\/ACM Trans. Netw. 31(3), 1369\u20131384 (2022)","journal-title":"IEEE\/ACM Trans. Netw."},{"issue":"CoNEXT4","key":"215_CR9","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3696385","volume":"2","author":"J Lee","year":"2024","unstructured":"J. Lee, D. Mohaisen, M.S. Kang, Measuring DNS-over-HTTPS downgrades: prevalence, techniques, and bypass strategies. Proc. ACM Netw. 2(CoNEXT4), 1\u201322 (2024)","journal-title":"Proc. ACM Netw."},{"key":"215_CR10","doi-asserted-by":"crossref","unstructured":"G.\u00a0Williams, P.\u00a0Pearce, in Proceedings of the 2024 ACM on Internet Measurement Conference, Seeds of scanning: Exploring the effects of datasets, methods, and metrics on ipv6 internet scanning (2024), pp. 295\u2013313","DOI":"10.1145\/3646547.3688449"},{"key":"215_CR11","doi-asserted-by":"crossref","unstructured":"N.\u00a0Kumar, R.\u00a0Surendiran, G.J. Samuel, N.\u00a0Bhavana, A.\u00a0Shirgire, A.J.G. Malar, A.\u00a0Qalid, in International Conference on Emergent Converging Technologies and Biomedical Systems, Health care dns tunnelling detection method via spiking neural network (Springer, 2023), pp. 715\u2013725","DOI":"10.1007\/978-981-99-8646-0_56"},{"key":"215_CR12","doi-asserted-by":"crossref","unstructured":"M.\u00a0Zuo, C.\u00a0Guo, H.\u00a0Xu, Z.\u00a0Zhang, Y.\u00a0Cheng, Metc: A hybrid deep learning framework for cross-network encrypted dns over https traffic detection and tunnel identification. Inf. Fusion 103125 (2025)","DOI":"10.1016\/j.inffus.2025.103125"},{"issue":"11","key":"215_CR13","doi-asserted-by":"publisher","first-page":"32945","DOI":"10.1007\/s11042-023-16956-9","volume":"83","author":"A Aggarwal","year":"2024","unstructured":"A. Aggarwal, M. Kumar, An ensemble framework for detection of dns-over-https (doh) traffic. Multimed. Tools Appl. 83(11), 32945\u201332972 (2024)","journal-title":"Multimed. Tools Appl."},{"issue":"6","key":"215_CR14","doi-asserted-by":"publisher","first-page":"6691","DOI":"10.11591\/ijece.v13i6.pp6691-6700","volume":"13","author":"J Fesl","year":"2023","unstructured":"J. Fesl, M. Konopa, J. Jel\u00ednek, A novel deep-learning based approach to dns over https network traffic detection. International Journal of Electrical and Computer Engineering (IJECE) 13(6), 6691\u20136700 (2023)","journal-title":"International Journal of Electrical and Computer Engineering (IJECE)"},{"key":"215_CR15","doi-asserted-by":"crossref","unstructured":"I.\u00a0Anjum, D.\u00a0Kostecki, E.\u00a0Leba, J.\u00a0Sokal, R.\u00a0Bharambe, W.\u00a0Enck, C.\u00a0Nita-Rotaru, B.\u00a0Reaves, in Proceedings of the 27th ACM on Symposium on Access Control Models and Technologies, Removing the reliance on perimeters for security using network views (2022), pp. 151\u2013162","DOI":"10.1145\/3532105.3535029"},{"key":"215_CR16","doi-asserted-by":"publisher","DOI":"10.1016\/j.fraope.2023.100010","volume":"2","author":"S Adiwal","year":"2023","unstructured":"S. Adiwal, B. Rajendran, S.D. Sudarsan et al., Dns intrusion detection (did)\u2014a snort-based solution to detect dns amplification and dns tunneling attacks. Franklin Open 2, 100,010 (2023)","journal-title":"Franklin Open"},{"key":"215_CR17","doi-asserted-by":"crossref","unstructured":"R.\u00a0Sommese, K.\u00a0Claffy, R.\u00a0van Rijswijk-Deij, A.\u00a0Chattopadhyay, A.\u00a0Dainotti, A.\u00a0Sperotto, M.\u00a0Jonker, in proceedings of the 22nd ACM Internet Measurement Conference, Investigating the impact of ddos attacks on dns infrastructure (2022), pp. 51\u201364","DOI":"10.1145\/3517745.3561458"},{"key":"215_CR18","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.103001","volume":"124","author":"A Niakanlahiji","year":"2023","unstructured":"A. Niakanlahiji, S. Orlowski, A. Vahid, J.H. Jafarian, Toward practical defense against traffic analysis attacks on encrypted dns traffic. Comput. Secur. 124, 103,001 (2023)","journal-title":"Comput. Secur."},{"key":"215_CR19","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102687","volume":"116","author":"A Nadler","year":"2022","unstructured":"A. Nadler, R. Bitton, O. Brodt, A. Shabtai, On the vulnerability of anti-malware solutions to DNS attacks. Comput. Secur. 116, 102,687 (2022)","journal-title":"Comput. Secur."},{"key":"215_CR20","doi-asserted-by":"crossref","unstructured":"F.\u00a0Bannat\u00a0Wala, S.\u00a0Campbell, M.\u00a0Kiran, in Proceedings of the 2023 on Systems and Network Telemetry and Analytics, Insights into doh: Traffic classification for dns over https in an encrypted network (2023), pp. 9\u201317","DOI":"10.1145\/3589012.3594895"},{"key":"215_CR21","doi-asserted-by":"crossref","unstructured":"G.\u00a0Akiwate, R.\u00a0Sommese, M.\u00a0Jonker, Z.\u00a0Durumeric, K.\u00a0Claffy, G.M. Voelker, S.\u00a0Savage, in Proceedings of the 22nd ACM Internet Measurement Conference, Retroactive identification of targeted dns infrastructure hijacking (2022), pp. 14\u201332","DOI":"10.1145\/3517745.3561425"},{"key":"215_CR22","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.103946","volume":"144","author":"C Li","year":"2024","unstructured":"C. Li, J. Chen, Z. Zhang, Z. Li, Y. Cheng, C. Ma, Dns root server resolution anomaly detection. Comput. Secur. 144, 103,946 (2024)","journal-title":"Comput. Secur."},{"key":"215_CR23","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102748","volume":"118","author":"D Akgun","year":"2022","unstructured":"D. Akgun, S. Hizal, U. Cavusoglu, A new ddos attacks intrusion detection model based on deep learning for cybersecurity. Comput. Secur. 118, 102,748 (2022)","journal-title":"Comput. Secur."},{"key":"215_CR24","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2023.109725","volume":"228","author":"V Quezada","year":"2023","unstructured":"V. Quezada, F. Astudillo-Salinas, L. Tello-Oquendo, P. Bernal, Real-time bot infection detection system using dns fingerprinting and machine-learning. Comput. Netw. 228, 109,725 (2023)","journal-title":"Comput. Netw."},{"key":"215_CR25","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103357","volume":"132","author":"Y Tu","year":"2023","unstructured":"Y. Tu, S. Liu, Q. Sun, Dns tunnelling detection by fusing encoding feature and behavioral feature. Comput. Secur. 132, 103,357 (2023)","journal-title":"Comput. Secur."},{"issue":"18","key":"215_CR26","doi-asserted-by":"publisher","first-page":"13039","DOI":"10.1007\/s00500-021-06608-1","volume":"27","author":"M Mittal","year":"2023","unstructured":"M. Mittal, K. Kumar, S. Behal, Deep learning approaches for detecting DDOS attacks: a systematic review. Soft. Comput. 27(18), 13039\u201313075 (2023)","journal-title":"Soft. Comput."},{"key":"215_CR27","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2023.109910","volume":"234","author":"M Moure-Garrido","year":"2023","unstructured":"M. Moure-Garrido, C. Campo, C. Garcia-Rubio, Real time detection of malicious doh traffic using statistical analysis. Comput. Netw. 234, 109,910 (2023)","journal-title":"Comput. Netw."},{"key":"215_CR28","doi-asserted-by":"crossref","unstructured":"M.\u00a0Moure-Garrido, C.\u00a0Campo, C.\u00a0Garcia-Rubio, in Proceedings of the 19th ACM International Symposium on Performance Evaluation of Wireless Ad Hoc, Sensor, & Ubiquitous Networks, Detecting malicious use of doh tunnels using statistical traffic analysis (2022), pp. 25\u201332","DOI":"10.1145\/3551663.3558605"},{"key":"215_CR29","doi-asserted-by":"crossref","unstructured":"A.R. Tapsoba, T.F. Ou\u00e9draogo, W.B.S. Zongo, in International Conference on Information Technology & Systems, Analysis of plaintext features in doh traffic for dga domains detection (Springer, 2024), pp. 127\u2013138","DOI":"10.1007\/978-3-031-54235-0_12"},{"issue":"4","key":"215_CR30","doi-asserted-by":"publisher","first-page":"549","DOI":"10.1007\/s11416-023-00462-5","volume":"19","author":"M Singh","year":"2023","unstructured":"M. Singh, M. Singh, S. Kaur, Identifying bot infection using neural networks on dns traffic. J. Comput. Virol. Hacking Tech. 19(4), 549\u2013563 (2023)","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"215_CR31","unstructured":"S.S. Monroy, A.K. Gupta, G.\u00a0Wahlstedt, Detection of malicious dns-over-https traffic: An anomaly detection approach using autoencoders (2023). arXiv preprint arXiv:2310.11325"},{"issue":"1","key":"215_CR32","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3579443","volume":"7","author":"M Zhang","year":"2023","unstructured":"M. Zhang, X. Li, B. Liu, J. Lu, Y. Zhang, J. Chen, H. Duan, S. Hao, X. Zheng, Detecting and measuring security risks of hosting-based dangling domains. Proc. ACM Meas. Anal. Comput. Syst. 7(1), 1\u201328 (2023)","journal-title":"Proc. ACM Meas. Anal. Comput. Syst."},{"key":"215_CR33","doi-asserted-by":"crossref","unstructured":"S.M.H. Mirsadeghi, in Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, Poster: in-switch defense against DNS amplification DDoS attacks (2024), pp. 4964\u20134966","DOI":"10.1145\/3658644.3691404"}],"container-title":["EURASIP Journal on Information Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s13635-025-00215-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s13635-025-00215-5\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s13635-025-00215-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,18]],"date-time":"2025-12-18T08:34:24Z","timestamp":1766046864000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1186\/s13635-025-00215-5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,12,18]]},"references-count":33,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["215"],"URL":"https:\/\/doi.org\/10.1186\/s13635-025-00215-5","relation":{"has-preprint":[{"id-type":"doi","id":"10.21203\/rs.3.rs-6414048\/v1","asserted-by":"object"}]},"ISSN":["2510-523X"],"issn-type":[{"value":"2510-523X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,12,18]]},"assertion":[{"value":"9 April 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"2 September 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"18 December 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"35"}}