Quantum-Kernel Detection of DNS Tunneling Under Entropy Overlap with DNSSEC-Confounded Traffic
Main Article Content
Abstract
DNS tunneling remains a difficult detection problem because malicious encoded payloads and benign high-entropy DNS traffic can produce similar lexical signatures. DNSSEC, cloud-service identifiers, and machine-generated naming systems further weaken entropy-only detection by creating benign traffic that appears statistically irregular. This paper presents a quantum-kernel support vector model for distinguishing DNS tunneling from ordinary benign DNS, benign high-entropy DNS, and DNSSEC-enriched benign DNS in a controlled four-class simulation. The model uses a sixteen-dimensional representation combining entropy, structural morphology, temporal behaviour, and DNSSEC-aware protocol indicators, followed by angle-encoded quantum-kernel evaluation. Results show that entropy alone is insufficient, while the full feature set achieves 0.9979 multiclass accuracy and macro F1 score, with zero DNSSEC-to-tunnel and benign-high-entropy-to-tunnel false-positive flow. In the binary tunnel-versus-non-tunnel setting, the full model achieves perfect classification in the present simulation. The findings show that quantum-kernel similarity is most effective when applied to a representation that captures the operational causes of DNS irregularity rather than entropy magnitude alone