{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,31]],"date-time":"2025-08-31T10:33:51Z","timestamp":1756636431269,"version":"3.41.0"},"reference-count":55,"publisher":"Institute of Electronics, Information and Communications Engineers (IEICE)","issue":"6","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEICE Trans. Inf. &amp; Syst."],"published-print":{"date-parts":[[2025,6,1]]},"DOI":"10.1587\/transinf.2024ntp0004","type":"journal-article","created":{"date-parts":[[2024,11,20]],"date-time":"2024-11-20T22:13:12Z","timestamp":1732140792000},"page":"526-534","source":"Crossref","is-referenced-by-count":2,"title":["DGA-Based Malware Communication Detection from DoH Traffic Using Hierarchical Machine Learning Analysis"],"prefix":"10.1587","volume":"E108.D","author":[{"given":"Rikima","family":"MITSUHASHI","sequence":"first","affiliation":[{"name":"Information Initiative Center, Hokkaido University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yong","family":"JIN","sequence":"additional","affiliation":[{"name":"Center for Information Infrastructure, Institute of Science Tokyo"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Katsuyoshi","family":"IIDA","sequence":"additional","affiliation":[{"name":"Information Initiative Center, Hokkaido University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yoshiaki","family":"TAKAI","sequence":"additional","affiliation":[{"name":"Information Initiative Center, Hokkaido University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"532","reference":[{"key":"1","doi-asserted-by":"crossref","unstructured":"[1] P. Hoffman and P. McManus, \u201cDNS Queries over HTTPS (DoH).\u201d RFC 8484, Oct. 2018. https:\/\/datatracker.ietf.org\/doc\/html\/rfc8484. Accessed June 20, 2024.","DOI":"10.17487\/RFC8484"},{"key":"2","doi-asserted-by":"crossref","unstructured":"[2] Z. Hu, L. Zhu, J. Heidemann, A. Mankin, D. Wessels, and P. Hoffman, \u201cSpecification for DNS over Transport Layer Security (TLS).\u201d RFC 7858, May 2016. https:\/\/datatracker.ietf.org\/doc\/html\/rfc7858. Accessed June 20, 2024.","DOI":"10.17487\/RFC7858"},{"key":"3","unstructured":"[3] \u201cSecure DNS Client over HTTPS (DoH).\u201d https:\/\/docs.microsoft.com\/en-us\/windows-server\/networking\/dns\/doh-client-support. Accessed June 20, 2024."},{"key":"4","unstructured":"[4] \u201cNEDNSOverHTTPSSettings: The DNS resolver settings for a DNS-over-HTTPS server.\u201d https:\/\/developer.apple.com\/documentation\/networkextension\/nednsoverhttpssettings. Accessed June 20, 2024."},{"key":"5","unstructured":"[5] \u201cDNS-over-HTTP\/3 in Android.\u201d https:\/\/security.googleblog.com\/2022\/07\/dns-over-http3-in-android.html. Accessed June 20, 2024."},{"key":"6","unstructured":"[6] \u201cSunburst: Supply Chain Attack Targets SolarWinds Users.\u201d https:\/\/symantec-enterprise-blogs.security.com\/blogs\/threat-intelligence\/sunburst-supply-chain-attack-solarwinds. Accessed June 20, 2024."},{"key":"7","doi-asserted-by":"publisher","unstructured":"[7] H. Ichise, Y. Jin, and K. Iida, \u201cAnalysis of DNS TXT Record Usage and Consideration of Botnet Communication Detection,\u201d IEICE Trans. Communications, vol.E101, no.1, pp.70-79, Oct. 2018. DOI:10.1587\/transcom.2017ITP0009 10.1587\/transcom.2017itp0009","DOI":"10.1587\/transcom.2017ITP0009"},{"key":"8","doi-asserted-by":"publisher","unstructured":"[8] H. Ichise, Y. Jin, K. Iida, and Y. Takai, \u201cNS record History Based Abnormal DNS traffic Detection Considering Adaptive Botnet Communication Blocking,\u201d IPSJ Journal of Information Processing, vol.28, pp.112-122, Feb. 2020. DOI:10.2197\/ipsjjip.28.112 10.2197\/ipsjjip.28.112","DOI":"10.2197\/ipsjjip.28.112"},{"key":"9","doi-asserted-by":"crossref","unstructured":"[9] Y. Iuchi, Y. Jin, H. Ichise, K. Iida, and Y. Takai, \u201cDetection and blocking of DGA-based bot infected computers by monitoring NXDOMAIN responses,\u201d Proc. 2020 7th IEEE Int. Conf. Cyber Security and Cloud Computing (CSCloud)\/2020 6th IEEE Int. Conf. Edge Computing and Scalable Cloud (EdgeCom), pp.82-87, Aug. 2020. DOI:10.1109\/CSCloud-EdgeCom49738.2020.00023 10.1109\/CSCloud-EdgeCom49738.2020.00023","DOI":"10.1109\/CSCloud-EdgeCom49738.2020.00023"},{"key":"10","doi-asserted-by":"crossref","unstructured":"[10] H. Ichise, Y. Jin, and K. Iida, \u201cPolicy-based detection and blocking system against abnormal applications by analyzing DNS traffic,\u201d Proc. 2023 22nd International Symposium on Communications and Information Technologies (ISCIT), pp.1-6, Oct. 2023. DOI:10.1109\/ISCIT57293.2023.10376042 10.1109\/ISCIT57293.2023.10376042","DOI":"10.1109\/ISCIT57293.2023.10376042"},{"key":"11","doi-asserted-by":"crossref","unstructured":"[11] J.Y. Lee, J.Y. Chang, and E.G. Im, \u201cDGA-based malware detection using DNS traffic analysis,\u201d Proc. Conference on Research in Adaptive and Convergent Systems (RACS \u201919), p.283-288, Sept. 2019. DOI:10.1145\/3338840.3355672 10.1145\/3338840.3355672","DOI":"10.1145\/3338840.3355672"},{"key":"12","doi-asserted-by":"crossref","unstructured":"[12] S. Ajmera and T. Pattanshetti, \u201cA survey report on identifying different machine learning algorithms in detecting domain generation algorithms within enterprise network,\u201d Proc. 2020 11th Int. Conf. Computing, Communication and Networking Technologies (ICCCNT), pp.1-5, July 2020. DOI:10.1109\/ICCCNT49239.2020.9225357 10.1109\/icccnt49239.2020.9225357","DOI":"10.1109\/ICCCNT49239.2020.9225357"},{"key":"13","doi-asserted-by":"publisher","unstructured":"[13] H. Suryotrisongko, Y. Musashi, A. Tsuneda, and K. Sugitani, \u201cRobust botnet DGA detection: Blending XAI and OSINT for cyber threat intelligence sharing,\u201d IEEE Access, vol.10, pp.34613-34624, March 2022. DOI:10.1109\/ACCESS.2022.3162588 10.1109\/access.2022.3162588","DOI":"10.1109\/ACCESS.2022.3162588"},{"key":"14","doi-asserted-by":"crossref","unstructured":"[14] M.A. Ayub, S. Smith, A. Siraj, and P. Tinker, \u201cDomain generating algorithm based malicious domains detection,\u201d Proc. 2021 8th IEEE Int. Conf. Cyber Security and Cloud Computing (CSCloud)\/2021 7th IEEE Int. Conf. Edge Computing and Scalable Cloud (EdgeCom), pp.77-82, June 2021. DOI:10.1109\/CSCloud-EdgeCom52276.2021.00024 10.1109\/cscloud-edgecom52276.2021.00024","DOI":"10.1109\/CSCloud-EdgeCom52276.2021.00024"},{"key":"15","doi-asserted-by":"crossref","unstructured":"[15] Y. Zhang, Y. Wu, and S. Jin, \u201cWhich DGA family does a malicious domain name belong to,\u201d Proc. 2020 IEEE Fifth Int. Conf. Data Science in Cyberspace (DSC), pp.53-60, July 2020. DOI:10.1109\/DSC50466.2020.00016 10.1109\/DSC50466.2020.00016","DOI":"10.1109\/DSC50466.2020.00016"},{"key":"16","doi-asserted-by":"crossref","unstructured":"[16] R.R. Curtin, A.B. Gardner, S. Grzonkowski, A. Kleymenov, and A. Mosquera, \u201cDetecting DGA domains with recurrent neural networks and side information,\u201d Proc. 14th Int. Conf. Availability, Reliability and Security (ARES \u201919), 2019. DOI:10.1145\/3339252.3339258 10.1145\/3339252.3339258","DOI":"10.1145\/3339252.3339258"},{"key":"17","unstructured":"[17] D. Plohmann, K. Yakdan, M. Klatt, J. Bader, and E. Gerhards-Padilla, \u201cA comprehensive measurement study of domain generating malware,\u201d Proc. 25th USENIX Security Symposium (USENIX Security 16), pp.263-278, Aug. 2016."},{"key":"18","doi-asserted-by":"crossref","unstructured":"[18] T. Chen and G. Carlos, \u201cXGBoost: A scalable tree boosting system,\u201d Proc. 22nd ACM SIGKDD Int. Conf. Knowledge Discovery and Data Mining, pp.785-794, Aug. 2016. DOI:10.1145\/2939672.2939785 10.1145\/2939672.2939785","DOI":"10.1145\/2939672.2939785"},{"key":"19","unstructured":"[19] G. Ke, Q. Meng, T. Finley, T. Wang, W. Chen, W. Ma, Q. Ye, and T.Y. Liu, \u201cLightGBM: A highly efficient gradient boosting decision tree,\u201d Proc. Advances in Neural Information Processing Systems, Dec. 2017."},{"key":"20","unstructured":"[20] L. Prokhorenkova, G. Gusev, A. Vorobev, A.V. Dorogush, and A. Gulin, \u201cCatBoost: Unbiased boosting with categorical features,\u201d Proc. Advances in Neural Information Processing Systems, pp.6639-6649, Dec. 2018."},{"key":"21","doi-asserted-by":"publisher","unstructured":"[21] R. Johnson and T. Zhang, \u201cLearning nonlinear functions using regularized greedy forest,\u201d IEEE Trans. Pattern Analysis and Machine Intelligence, vol.36, no.5, pp.942-954, May 2014. DOI:10.1109\/TPAMI.2013.159 10.1109\/tpami.2013.159","DOI":"10.1109\/TPAMI.2013.159"},{"key":"22","unstructured":"[22] \u201cThe DGA of PadCrypt.\u201d https:\/\/bin.re\/blog\/the-dga-of-padcrypt\/. Accessed June 20, 2024."},{"key":"23","unstructured":"[23] \u201cThe DGA of Sisron.\u201d https:\/\/bin.re\/blog\/the-dga-of-sisron\/. Accessed June 20, 2024."},{"key":"24","unstructured":"[24] \u201cTinba\u2019s DGA Adds Other Top Level Domains.\u201d https:\/\/bin.re\/blog\/new-top-level-domains-for-tinbas-dga\/. Accessed June 20, 2024."},{"key":"25","doi-asserted-by":"publisher","unstructured":"[25] A. Mills and P. Legg, \u201cInvestigating Anti-Evasion Malware Triggers Using Automated Sandbox Reconfiguration Techniques,\u201d Journal of Cybersecurity and Privacy, vol.1, no.1, pp.19-39, 2021. 10.3390\/jcp1010003","DOI":"10.3390\/jcp1010003"},{"key":"26","unstructured":"[26] \u201cThe DGA of Zloader.\u201d https:\/\/bin.re\/blog\/the-dga-of-zloader\/. Accessed June 20, 2024."},{"key":"27","doi-asserted-by":"crossref","unstructured":"[27] R. Mitsuhashi, Y. Jin, K. Iida, T. Shinagawa, and Y. Takai, \u201cDetection of DGA-based malware communications from DoH traffic using machine learning analysis,\u201d Proc. 2023 IEEE 20th Consumer Communications &amp; Networking Conference (CCNC), pp.224-229, Jan. 2023. DOI:10.1109\/CCNC51644.2023.10059835 10.1109\/ccnc51644.2023.10059835","DOI":"10.1109\/CCNC51644.2023.10059835"},{"key":"28","doi-asserted-by":"crossref","unstructured":"[28] L. Csikor, H. Singh, M.S. Kang, and D.M. Divakaran, \u201cPrivacy of DNS-over-HTTPS: Requiem for a dream?,\u201d Proc. 2021 IEEE European Symposium on Security and Privacy (EuroS&amp;P), pp.252-271, Sept. 2021. DOI:10.1109\/EuroSP51992.2021.00026 10.1109\/eurosp51992.2021.00026","DOI":"10.1109\/EuroSP51992.2021.00026"},{"key":"29","doi-asserted-by":"crossref","unstructured":"[29] D. Vekshin, K. Hynek, and T. Cejka, \u201cDoH insight: Detecting DNS over HTTPS by machine learning,\u201d Proc. 15th Int. Conf. Availability, Reliability and Security (ARES \u201920), Aug. 2020. DOI:10.1145\/3407023.3409192 10.1145\/3407023.3409192","DOI":"10.1145\/3407023.3409192"},{"key":"30","unstructured":"[30] \u201cCloudflare Tunnel (Cloudflared).\u201d https:\/\/developers.cloudflare.com\/cloudflare-one\/connections\/connect-apps. Accessed June 20, 2024."},{"key":"31","unstructured":"[31] \u201cAmazon Alexa Voice AI.\u201d https:\/\/developer.amazon.com\/en-US\/alexa\/. Accessed June 20, 2024."},{"key":"32","doi-asserted-by":"publisher","unstructured":"[32] M. Trevisan, F. Soro, M. Mellia, I. Drago, and R. Morla, \u201cAttacking DoH and ECH: Does server name encryption protect users\u2019 privacy?,\u201d ACM Trans. Internet Technology, vol.23, no.1, pp.1-22, Feb. 2023. DOI:10.1145\/3570726 10.1145\/3570726","DOI":"10.1145\/3570726"},{"key":"33","doi-asserted-by":"crossref","unstructured":"[33] F. Bannat Wala, S. Campbell, and M. Kiran, \u201cInsights into DoH: Traffic classification for DNS over HTTPS in an encrypted network,\u201d Proc. 2023 on Systems and Network Telemetry and Analytics (SNTA \u201923), pp.9-17, June 2023. DOI:10.1145\/3589012.3594895 10.1145\/3589012.3594895","DOI":"10.1145\/3589012.3594895"},{"key":"34","doi-asserted-by":"crossref","unstructured":"[34] M. MontazeriShatoori, L. Davidson, G. Kaur, and A. Habibi Lashkari, \u201cDetection of DoH tunnels using time-series classification of encrypted traffic,\u201d Proc. 2020 IEEE Intl. Conf. Dependable, Autonomic and Secure Computing, Intl. Conf. Pervasive Intelligence and Computing, Intl. Conf. Cloud and Big Data Computing, Intl. Conf. Cyber Science and Technology Congress (DASC\/PiCom\/CBDCom\/CyberSciTech), pp.63-70, Aug. 2020.DOI:10.1109\/DASC-PICom-CBDCom-CyberSciTech49142.2020.00026 10.1109\/DASC-PICom-CBDCom-CyberSciTech49142.2020.00026","DOI":"10.1109\/DASC-PICom-CBDCom-CyberSciTech49142.2020.00026"},{"key":"35","unstructured":"[35] \u201cCIRA-CIC-DoHBrw-2020.\u201d https:\/\/www.unb.ca\/cic\/datasets\/dohbrw-2020.html. Accessed June 20, 2024."},{"key":"36","doi-asserted-by":"crossref","unstructured":"[36] Y. Khodjaeva and N. Zincir-Heywood, \u201cNetwork flow entropy for identifying malicious behaviours in DNS tunnels,\u201d Proc. 16th Int. Conf. Availability, Reliability and Security (ARES \u201921), Aug. 2021. DOI: 10.1145\/3465481.3470089 10.1145\/3465481.3470089","DOI":"10.1145\/3465481.3470089"},{"key":"37","doi-asserted-by":"crossref","unstructured":"[37] R. Mitsuhashi, A. Satoh, Y. Jin, K. Iida, T. Shinagawa, and Y. Takai, \u201cIdentifying malicious DNS tunnel tools from DoH traffic using hierarchical machine learning classification,\u201d Proc. 24th Int. Conf. Information Security (ISC 2021), pp.238-256, Nov. 2021. DOI:10.1007\/978-3-030-91356-4_13 10.1007\/978-3-030-91356-4_13","DOI":"10.1007\/978-3-030-91356-4_13"},{"key":"38","doi-asserted-by":"publisher","unstructured":"[38] R. Mitsuhashi, Y. Jin, K. Iida, T. Shinagawa, and Y. Takai, \u201cMalicious DNS tunnel tool recognition using persistent DoH traffic analysis,\u201d IEEE Trans. Network and Service Management, vol.20, no.2, pp.2086-2095, June 2023. DOI:10.1007\/978-3-030-91356-4_13 10.1109\/tnsm.2022.3215681","DOI":"10.1109\/TNSM.2022.3215681"},{"key":"39","unstructured":"[39] \u201cDoH-Tunnel-Traffic-HKD dataset.\u201d https:\/\/github.com\/doh-traffic-dataset\/DoH-Tunnel-Traffic-HKD. Accessed June 20, 2024."},{"key":"40","doi-asserted-by":"crossref","unstructured":"[40] Y. Zhang, W. Sun, and S. Zhang, \u201cIdentify VPN traffic under HTTPS tunnel using three-dimensional sequence features,\u201d Proc. 2022 11th Int. Conf. Networks, Communication and Computing (ICNCC \u201922), pp.18-23, Dec. 2022. DOI:10.1145\/3579895.3579899 10.1145\/3579895.3579899","DOI":"10.1145\/3579895.3579899"},{"key":"41","doi-asserted-by":"publisher","unstructured":"[41] T. Zebin, S. Rezvy, and Y. Luo, \u201cAn explainable AI-based intrusion detection system for DNS over HTTPS (DoH) attacks,\u201d IEEE Trans. Information Forensics and Security, vol.17, pp.2339-2349, June 2022. DOI:10.1109\/TIFS.2022.3183390 10.1109\/tifs.2022.3183390","DOI":"10.1109\/TIFS.2022.3183390"},{"key":"42","doi-asserted-by":"crossref","unstructured":"[42] L. Jiao, Y. Zhu, X. Fu, Y. Zhou, F. Qin, and Q. Liu, \u201cCCSv6: A detection model for DNS-over-HTTPS tunnel using attention mechanism over IPv6,\u201d Proc. 2023 IEEE Symposium on Computers and Communications (ISCC), pp.1327-1330, July 2023. DOI:10.1109\/ISCC58397.2023.10218057 10.1109\/iscc58397.2023.10218057","DOI":"10.1109\/ISCC58397.2023.10218057"},{"key":"43","doi-asserted-by":"crossref","unstructured":"[43] B. Wang, G. Xiong, G. Gou, J. Song, Z. Li, and Q. Yang, \u201cIdentifying DoH tunnel traffic using core feathers and machine learning method,\u201d Proc. 2023 26th Int. Conf. Computer Supported Cooperative Work in Design (CSCWD), pp.814-819, May 2023. DOI:10.1109\/CSCWD57460.2023.10152678 10.1109\/cscwd57460.2023.10152678","DOI":"10.1109\/CSCWD57460.2023.10152678"},{"key":"44","doi-asserted-by":"crossref","unstructured":"[44] Q. Pan, H. Yan, Z. Qin, and B. Qi, \u201cPACLASS: A lightweight classification framework on DNS-over-HTTPS,\u201d Proc. IEEE Int. Conf. Communications (ICC \u201923), pp.3805-3810, May 2023. DOI:10.1109\/ICC45041.2023.10279398 10.1109\/icc45041.2023.10279398","DOI":"10.1109\/ICC45041.2023.10279398"},{"key":"45","doi-asserted-by":"crossref","unstructured":"[45] Y. Qiu, B. Li, L. Jiao, Y. Zhu, and Q. Liu, \u201cDetection of DoH tunnels with dual-tier classifier,\u201d Proc. 2022 18th Int. Conf. Mobility, Sensing and Networking (MSN), pp.417-421, Dec. 2022. DOI: 10.1109\/MSN57253.2022.00073 10.1109\/msn57253.2022.00073","DOI":"10.1109\/MSN57253.2022.00073"},{"key":"46","doi-asserted-by":"crossref","unstructured":"[46] R. Rader, K. Jerabek, and O. Rysavy, \u201cDetecting DoH-based data exfiltration: FluBot malware case study,\u201d Proc. 2023 IEEE 48th Conference on Local Computer Networks (LCN), pp.1-4, Oct. 2023. DOI:10.1109\/LCN58197.2023.10223341 10.1109\/lcn58197.2023.10223341","DOI":"10.1109\/LCN58197.2023.10223341"},{"key":"47","unstructured":"[47] \u201cDohlyzer.\u201d https:\/\/github.com\/ahlashkari\/DoHlyzer. Accessed June 20, 2024."},{"key":"48","doi-asserted-by":"crossref","unstructured":"[48] S. R, S.S. Ayachit, V. Patil, and A. Singh, \u201cCompetitive analysis of the top gradient boosting machine learning algorithms,\u201d Proc. 2020 2nd Int. Conf. Advances in Computing, Communication Control and Networking (ICACCCN), pp.191-196, Dec. 2020. DOI:10.1109\/ICACCCN51052.2020.9362840 10.1109\/icacccn51052.2020.9362840","DOI":"10.1109\/ICACCCN51052.2020.9362840"},{"key":"49","unstructured":"[49] \u201cRegularized Greedy Forest.\u201d https:\/\/github.com\/RGF-team\/rgf. Accessed June 20, 2024."},{"key":"50","unstructured":"[50] \u201cXGBoost Documentation - Xgboost Parameters.\u201d https:\/\/xgboost.readthedocs.io\/en\/latest\/parameter.html. Accessed June 20, 2024."},{"key":"51","unstructured":"[51] \u201cLightGBM Documentation - Parameters.\u201d https:\/\/lightgbm.readthedocs.io\/en\/latest\/Parameters-Tuning.html. Accessed June 20, 2024."},{"key":"52","unstructured":"[52] \u201cCatBoost Documentation - Parameters.\u201d https:\/\/catboost.ai\/en\/docs\/concepts\/parameter-tuning. Accessed June 20, 2024."},{"key":"53","unstructured":"[53] \u201cRGF for Python Documentation - Tuning Hyperparameters.\u201dhttps:\/\/github.com\/RGF-team\/rgf\/tree\/master\/python-package. Accessed June 20, 2024."},{"key":"54","unstructured":"[54] \u201cVirusShare.\u201d https:\/\/virusshare.com\/. Accessed June 20, 2024."},{"key":"55","unstructured":"[55] \u201cDoH-DGA-Malware-Traffic-HKD dataset.\u201d https:\/\/github.com\/rikima-mitsuhashi\/DoH-DGA-Malware-Traffic-HKD. AccessedJune 20, 2024."}],"container-title":["IEICE Transactions on Information and Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.jstage.jst.go.jp\/article\/transinf\/E108.D\/6\/E108.D_2024NTP0004\/_pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,7]],"date-time":"2025-06-07T03:43:02Z","timestamp":1749267782000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.jstage.jst.go.jp\/article\/transinf\/E108.D\/6\/E108.D_2024NTP0004\/_article"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,1]]},"references-count":55,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2025]]}},"URL":"https:\/\/doi.org\/10.1587\/transinf.2024ntp0004","relation":{},"ISSN":["0916-8532","1745-1361"],"issn-type":[{"type":"print","value":"0916-8532"},{"type":"electronic","value":"1745-1361"}],"subject":[],"published":{"date-parts":[[2025,6,1]]},"article-number":"2024NTP0004"}}