A Multi-Layered Defense AES-GCM and Dragonfly-ECC Based Protocol for Mitigating Spoofing Attacks in DNS Systems

References
- Alzoubi, Y. I., A. Aljaafreh. Blockchain-Fog Computing Integration Applications: A Systematic Review. – Cybernetics and Information Technologies, Vol. 23, 2023, No 1, pp. 3-37.
- Hussain, M. A., H. Jin, Z. A. Hussien, Z. A. Abduljabbar, S. H. Abbdal, A. Ibrahim. Enc-DNS-HTTP: Utilising DNS Infrastructure to Secure Web Browsing. – Security and Communication Networks, 2017. DOI: 10.1155/2017/9479476.
- Blancaflor, E. B., J. O. Duldulao, J. V. E. Espeño, G. S. M. Patag, M. A. T. Menor, G. L. Intal. Advanced Phishing Techniques: Analyzing Adversary-inthe-Middle and Browser-in-the-Browser Attacks in Modern Cybersecurity. – Cybernetics and Information Technologies, Vol. 25, 2025, No 1, pp. 55-77.
- Zhraw, D. S., M. A. Hussain, Z. A. Abduljabbar, V. O. Nyangaresi, A. J. Y. Aldarwish. Chronological Review of MITM Attacks: Challenges, Solutions and Recommendations. – In: Proc. of Computer Science on-line Conference, Springer, 2025, pp. 202-220. DOI: 10.1007/978-3-032-03406-9_13.
- Btoush, A., A. Abadleh, A. A. Alkasasbeh et al. The Intrusion Detection and Recovery of Deauthentication Frame in WPA3 SAE. – Research Square (Preprint), 2024. DOI: 10.21203/rs.3.rs-4856594/v1.
- Hussain, M. A., H. Jin, Z. A. Hussien, Z. A. Abduljabbar, S. H. Abbdal, A. Ibrahim. DNS Protection against Spoofing and Poisoning Attacks. – In: Proc. of International Conference on Information Science and Control Engineering, 2016, pp. 1308-1312. DOI: 10.1109/ICISCE.2016.279.
- Hussain, M. A., et al. Web Application Database Protection from SQLIA Using Permutation Encoding. – In: Proc. of ACM International Conference Proceedings Series, 2021, pp. 13-21. DOI: 10.1145/3459955.3460594.
- Iyengar, N. C. S. N., G. Ganapathy. Trilateral Trust-Based Defense Mechanism against DDoS Attacks in Cloud Computing Environment. – Cybernetics and Information Technologies, Vol. 15, 2015, No 2, pp. 119-140.
- Lancrenon, J., M. Š krobot. On the Provable Security of the Dragonfly Protocol. – In: Information Security (ISC’2015), Lecture Notes in Computer Science, Vol. 9290, Springer, 2015. DOI: 10.1007/978-3-319-23318-5_14.
- Clarke, D., F. Hao. Cryptanalysis of the Dragonfly Key Exchange Protocol. – IET Information Security, Vol. 8, 2014, pp. 283-289. DOI: 10.1049/iet-ifs.2013.0081.
- Alharbi, E., N. Alsulami, O. Batarfi. An Enhanced Dragonfly Key Exchange Protocol against Offline Dictionary Attack. – Journal of Information Security, 2015, pp. 69-81. DOI: 10.4236/jis.2015.62008.
- Braga, D. D. A., N. Kulatova, M. Sabt, P. Fouque, K. Bhargavan. From Dragondoom to Dragonstar: Side-Channel Attacks and Formally Verified Implementation of WPA3 Dragonfly Handshake. – In: Proc. of IEEE European Symposium on Security and Privacy (EuroS&P), 2023, pp. 707-723. DOI: 10.1109/EuroSP57164.2023.00048.
- Heftrig, E., H. Shulman, M. Waidner. Off-Path DNSSEC Downgrade Attacks. – In: ACM SIGCOMM Conference, 2023, pp. 1120-1122. DOI: 10.1145/3603269.3610840.
- Harkins, D. Dragonfly Key Exchange. – RFC 7664, Internet Engineering Task Force, 2015. DOI: 10.17487/RFC7664.
- Barker, E. Recommendation for Pairwise Key-Establishment Schemes Using Discrete Logarithm Cryptography. – NIST Special Publication 800-56A, 2018. DOI: 10.6028/NIST.SP.800-56Ar3.
- Krawczyk, H., P. Eronen. HMAC-Based Extract-and-Expand Key Derivation Function (HKDF). – RFC 5869, 2010. DOI: 10.17487/RFC5869.
- Blaise, O. O., A. Wumi, U. Alfred. Enhancing DNS Performance with Efficient Cryptographic Algorithms: A Comparative Study of DoT Frameworks. – Asian Journal of Computer Science and Technology, Vol. 13, 2024, No 2, pp. 48-55. DOI: 10.70112/ajcst-2024.13.2.4288.
- Padmavathi, G., A. SabithaBanu. Hybrid Detection and Mitigation of DNS Protocol MITM Attack Based on Firefly Algorithm with Elliptical Curve Cryptography. – Engineering and Technology for Public Health, Vol. 8, 2022, No 4. DOI: 10.4108/eetpht.v9i1.3177.
- Mattsson, J. P. Collision-Based Attacks on Block Cipher Modes: Exploiting Collisions and their Absence. – Cryptology ePrint Archive, 2024.
- Maksutov, A. A., I. A. Cherepanov, M. S. Alekseev. Detection and Prevention of DNS Spoofing Attacks. – In: Proc. of Siberian Symposium on Data Science and Engineering, 2017, pp. 84-87. DOI: 10.1109/SSDSE.2017.8071970.
- Iwata, T., K. Ohashi, K. Minematsu. Breaking and Repairing GCM Security Proofs. – In: Proc. of Annual Cryptology Conference, Springer, 2012, pp. 31-49. DOI: 10.1007/978-3-642-32009-5_3.
- Yu, H., X. Yuchi, X. Yang, H. Li, X. Yang, W. Wang. DNS-Sensor: A Sensor-Driven Architecture for Real-Time DNS Cache Poisoning Detection and Mitigation. – Sensors, Vol. 25, 2025, 6884. DOI: 10.3390/s25226884.
- Heftrig, E., H. Shulman, N. Vog el, M. Waidner. The Harder You Try, the Harder You Fail: The KeyTrap Denial-of-Service Algorithmic Complexity Attacks on DNSSEC. – In: Proc. of ACM SIGSAC Conference on Computer and Communications Security (CCS’24), 2024, pp. 497-510. DOI: 10.1145/3658644.3670389.
- Bellare, M., B. Tackmann. The Multi-User Security of Authenticated Encryption: AES-GCM in TLS 1.3. – In: Advances in Cryptology (CRYPTO 2016), LNCS. Vol. 9814. Springer, 2016, pp. 247-276. DOI: 10.1007/978-3-662-53018-4_10.
- Vanhoef, M. Dragonblood: Analyzing the Dragonfly Handshake of WPA3 and EAP-pwd. – In: Proc. of IEEE Symposium on Security and Privacy, 2020, pp. 517-533. DOI: 10.1109/SP40000.2020.00031.
- Dawood, M., et al. The Impact of Domain Name Server (DNS) over HTTPS on Cybersecurity: Limitations, Challenges, and Detection Techniques. – Computers, Materials and Continua, Vol. 80, 2024, No 3, pp. 4513-4542. DOI: 10.32604/cmc.2024.050049.
- Patil, D. A., G. Shyamala. A Comprehensive Survey on Securing the Social Internet of Things: Protocols, Threat Mitigation, Technological Integrations, Tools, and Performance Metrics. – Scientific Reports, Vol. 15, 2025, 40190. DOI: 10.1038/s41598-025-23865-4.
- Rotuna, C. I., I. S. Sacala, A. Alexandru. Towards Proactive Domain Name Security: An Adaptive System for .ro Domains Reputation Analysis. – Future Internet, Vol. 17, 2025, No 10, 478. DOI: 10.3390/fi17100478.
- Luo, S. Blockchain-Enabled Decentralized End Hopping for Proactive Network Defence. – Telecom, Vol. 7, 2026, No 2, 28. DOI: 10.3390/telecom7020028.
- Amirkhanova, G., S. Ismailov, A. Amirkhanov, S. Adilzhanova. A Lightweight End-to-End Encrypted Data Pipeline for IIoT. – Information, Vol. 17, 2026, No 1, 33. DOI: 10.3390/info17010033.
- AbuAl-Haija, Q., M. Alohaly, A. Odeh. A Lightweight Double-Stage Scheme to Identify Malicious DNS over HTTPS Traffic Using a Hybrid Learning Approach. – Sensors, Vol. 23, 2023, No 7, 3489. DOI: 10.3390/s23073489.
- Kundu, A., V. Chakraborty, R. Kompella. Post-Quantum Cryptographic Analysis of Message Transformations across the Network Stack. – arXiv Preprint, 2026. DOI: 10.48550/arXiv.2604.08480.
- Agrawal, N. K., S. Alam, H. Raghav. OSI Model: The Basic Structure of Network Communication. – International Journal of Recent Technology and Engineering, Vol. 9, 2021, No 5, pp. 66-69. DOI: 10.35940/ijrte.D4991.019521.
DOI: https://doi.org/10.2478/cait-2026-0025 | Journal eISSN: 1314-4081 | Journal ISSN: 1311-9702 (formerly 1314-4081)
Language: English
Page range: 25 - 49
Submitted on: Mar 19, 2026
Accepted on: May 25, 2026
Published on: Sep 9, 2026
Published by: Bulgarian Academy of Sciences, Institute of Information and Communication Technologies
In partnership with: Paradigm Publishing Services
Keywords:
Related subjects:
© 2026 Sura Aljassim, Mohammed Abdulridha Hussain, Zaid Ameen Abduljabbar, Hamid Ali Abed Al-Asadi, Vincent Omollo Nyangaresi, Ali Hasan Ali, Abdulla J. Y. Aldarwish, published by Bulgarian Academy of Sciences, Institute of Information and Communication Technologies
This work is licensed under the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 License.