Improved Domain Name System Threat Detection using an RPZ and DGA-based approach incorporating Machine Learning
R. Guy Edouard Bouda, Abdoulaye Séré, Frédéric Ouédraogo · 2025
A domain name is a unique identifier of a resource on the internet. The resource can be an application, a website, a computer, a smartphone. The domain name is used to prevent Internet users from having to remember and use addresses made up of a series of numbers and/or letters, very difficult or even impossible for a human being to memorize for each of the resources on the internet. The Domain Name System (DNS) functions as the backbone of the Internet. However, due to the lack of built-in security features during its initial protocol design, DNS has been exploited for various malicious activities such as spreading malware, launching distributed denial of service (DDoS) attacks, facilitating fraudulent hosting and phishing, among others. This article proposes an approach using a filtering method that combines RPZ (Response Policy Zone), DGA (Domain Generation Algorithm) detection, and machine learning through a Random Forest classifier to strengthen network security by blocking malicious domains, including those dynamically generated by malware. By integrating artificial intelligence, our method enhances traditional filtering techniques with intelligent domain classification, enabling proactive detection of previously unseen threats. The combination of RPZ for blocking known malicious domains and AI-powered detection of DGA-generated domains offers a more comprehensive and adaptive defense against online attacks.The proposed method achieved a detection accuracy of 99.94% and reduced false positives by 49 compared to RPZ-based combinations, while maintaining high accuracy and eliminating false negatives, demonstrating its efficiency in real-world network environments.