A Multi-Layered Defense AES-GCM and Dragonfly-ECC Based Protocol for Mitigating Spoofing Attacks in DNS Systems

Abstract
Domain Name System (DNS) is the way that Internet domain names are located and translated into IP addresses. The security architecture of the original design suffers from a lack of strength, as it was designed without built-in security. Among the most pervasive threats is DNS spoofing, in which attackers inject fraudulent responses that redirect users to malicious websites, thereby compromising both security and data integrity. This threat necessitates a defense mechanism that embeds protection directly within the DNS communication workflow. We propose a multi-layered defense approach that protects the communication channel between server and client without needing alteration to the network infrastructure. It combines the Dragonfly PAKE protocol with AES-GCM authenticated encryption to secure DNS responses. Practical experiments through a virtual platform showed that the proposed method is able to thwart attacks better than DoH and DNSSEC. The novelty of this work lies in combining Dragonfly-ECC key exchange with AES-256-GCM encryption in a protocol designed for DNS response protection, while employing HKDF-based nonce derivation that avoids transmitting nonces over the network. The security analysis based on SVO logic verified the integrity and reliability of the protocol.
© 2026 Sura Aljassim, Mohammed Abdulridha Hussain, Zaid Ameen Abduljabbar, Hamid Ali Abed Al-Asadi, Vincent Omollo Nyangaresi, Ali Hasan Ali, Abdulla J. Y. Aldarwish, published by Bulgarian Academy of Sciences, Institute of Information and Communication Technologies
This work is licensed under the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 License.