Next Article in Journal
Interoperable Semantic Systems in Public Administration: AI-Driven Data Mining from Law-Enforcement Reports
Next Article in Special Issue
Mapping the Chemical Space of Antiviral Peptides with Half-Space Proximal and Metadata Networks Through Interactive Data Mining
Previous Article in Journal
Bridging Domains: Advances in Explainable, Automated, and Privacy-Preserving AI for Computer Science and Cybersecurity
Previous Article in Special Issue
Quantum Computing in Data Science and STEM Education: Mapping Academic Trends and Analyzing Practical Tools
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

Rule-Based eXplainable Autoencoder for DNS Tunneling Detection

by
Giacomo De Bernardi
1,
Giovanni Battista Gaggero
2,*,
Fabio Patrone
2,
Sandro Zappatore
2,
Mario Marchese
2 and
Maurizio Mongelli
1
1
IEIIT Institute, Italian National Research Council (CNR), 16149 Genoa, Italy
2
Department of Electrical, Electronics and Telecommunications Engineering and Naval Architecture (DITEN), University of Genoa, 16145 Genoa, Italy
*
Author to whom correspondence should be addressed.
Computers 2025, 14(9), 375; https://doi.org/10.3390/computers14090375
Submission received: 6 June 2025 / Revised: 18 August 2025 / Accepted: 4 September 2025 / Published: 8 September 2025

Abstract

Artificial Intelligence (AI) and Machine Learning (ML) are employed in numerous fields and applications. Even if most of these approaches offer a very good performance, they are affected by the “black-box” problem. The way they operate and make decisions is complex and difficult for human users to interpret, making the systems impossible to manually adjust in case they make trivial (from a human viewpoint) errors. In this paper, we show how a “white-box” approach based on eXplainable AI (XAI) can be applied to the Domain Name System (DNS) tunneling detection problem, a cybersecurity problem already successfully addressed by “black-box” approaches, in order to make the detection explainable. The obtained results show that the proposed solution can achieve a performance comparable to the one offered by an autoencoder-based solution while offering a clear view of how the system makes its choices and the possibility of manual analysis and adjustments.
Keywords: DNS tunnelling; intrusion detection system; eXplainable AI; statistical traffic analysis DNS tunnelling; intrusion detection system; eXplainable AI; statistical traffic analysis

Share and Cite

MDPI and ACS Style

De Bernardi, G.; Gaggero, G.B.; Patrone, F.; Zappatore, S.; Marchese, M.; Mongelli, M. Rule-Based eXplainable Autoencoder for DNS Tunneling Detection. Computers 2025, 14, 375. https://doi.org/10.3390/computers14090375

AMA Style

De Bernardi G, Gaggero GB, Patrone F, Zappatore S, Marchese M, Mongelli M. Rule-Based eXplainable Autoencoder for DNS Tunneling Detection. Computers. 2025; 14(9):375. https://doi.org/10.3390/computers14090375

Chicago/Turabian Style

De Bernardi, Giacomo, Giovanni Battista Gaggero, Fabio Patrone, Sandro Zappatore, Mario Marchese, and Maurizio Mongelli. 2025. "Rule-Based eXplainable Autoencoder for DNS Tunneling Detection" Computers 14, no. 9: 375. https://doi.org/10.3390/computers14090375

APA Style

De Bernardi, G., Gaggero, G. B., Patrone, F., Zappatore, S., Marchese, M., & Mongelli, M. (2025). Rule-Based eXplainable Autoencoder for DNS Tunneling Detection. Computers, 14(9), 375. https://doi.org/10.3390/computers14090375

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop