A comparative analysis of supervised machine learning models for threat detection in domain name system

Ahmad, Amir Haris and Ab Ghani, Hadhrami and Mirza, Muhammad Muzzammal and Anwar, Muhammad (2026) A comparative analysis of supervised machine learning models for threat detection in domain name system. Mathematical Sciences and Informatics Journal (MIJ), 7 (1). pp. 117-126. ISSN 2735-0703

Official URL: https://mijuitm.com.my

Identification Number (DOI): 10.24191/mij.v7i1.11939

Abstract

The Domain Name System (DNS) is an important element of the Internet. It serves as the standard method for translating human-readable domain names into machine-readable IP addresses. Despite its importance, DNS has persistently challenged by various threats that compromise its security and functionality. Various machine learning models have been proposed to detect and classify DNS attacks. This work aims to provide a comparative analysis of three supervised machine learning models: Random Forest, Vector-Based, and XGBoost. These models were trained and tested for the classification of DNS threats in 11 different categories. Among all three models, XGBoost consistently outperforms Random Forest and the Vector-Based model in terms of accuracy, speed, confidence, precision, recall, and F1-score. It provides the highest detection accuracy (56.4%), the fastest processing speed (10,263 domains/sec), and the lowest false alarm rate (4.3%), making it the most reliable choice for malicious domain detection. In addition to examining the DNS threat landscape and existing challenges, this research also highlights the strengths and limitations of the existing state of the art and provides future research directions for researchers to understand DNS vulnerabilities and current gaps in their mitigation techniques.

Metadata

Item Type: Article
Creators:
Creators
Email / ID Num.
Ahmad, Amir Haris
UNSPECIFIED
Ab Ghani, Hadhrami
hadhrami.ag@umk.edu.my
Mirza, Muhammad Muzzammal
UNSPECIFIED
Anwar, Muhammad
anwar.muhammad@ue.edu.pk
Subjects: Q Science > QA Mathematics > Instruments and machines > Electronic Computers. Computer Science
T Technology > TK Electrical engineering. Electronics. Nuclear engineering > Telecommunication > Computer networks. General works. Traffic monitoring
Divisions: Universiti Teknologi MARA, Perak > Tapah Campus > Faculty of Computer and Mathematical Sciences
Journal or Publication Title: Mathematical Sciences and Informatics Journal (MIJ)
UiTM Journal Collections: UiTM Journals > Mathematical Science and Information Journal (MIJ)
ISSN: 2735-0703
Volume: 7
Number: 1
Page Range: pp. 117-126
Keywords: DSN security, Supervised machine learning, Threat detection, Comparative analysis
Date: April 2026
URI: https://ir.uitm.edu.my/id/eprint/141737
Edit Item
Edit Item

Download

[thumbnail of 141737.pdf] Text
141737.pdf

Download (389kB)

ID Number

141737

Indexing

Altmetric
PlumX
Dimensions

Statistic

Statistic details