已入深夜,您辛苦了!由于当前在线用户较少,发布求助请尽量完整地填写文献信息,科研通机器人24小时在线,伴您度过漫漫科研夜!祝你早点完成任务,早点休息,好梦!

Classifying Malicious Domains using DNS Traffic Analysis

网络钓鱼 恶意软件 僵尸网络 计算机科学 域名系统 计算机安全 领域(数学分析) 审查 互联网 黑名单 域名 万维网 数学 数学分析
作者
Samaneh Mahdavifar,Nasim Maleki,Arash Habibi Lashkari,Matt Broda,Amir H. Razavi
标识
DOI:10.1109/dasc-picom-cbdcom-cyberscitech52372.2021.00024
摘要

Malicious domains are one of the major threats that have jeopardized the viability of the Internet over the years. Threat actors usually abuse the Domain Name System (DNS) to lure users to be victims of malicious domains hosting drive-by-download malware, botnets, phishing websites, or spam messages. Each year, many large corporations are impacted by these threats, resulting in huge financial losses in a single attack. Thus, detecting and classifying a malicious domain in a timely manner is essential. Previously, filtering the domains against blacklists was the only way to detect malicious domains, however, this approach was unable to detect newly generated domains. Recently, Machine Learning (ML) techniques have helped to enhance the detection capability of domain vetting systems. A solid feature engineering mechanism plays a pivotal role in boosting the performance of any ML model. Therefore, we have extracted effective and practical features from DNS traffic categorizing them into three groups of lexical-based, DNS statistical-based, and third party-based features. Third party features are biographical information about a specific domain extracted from third party APIs. The benign to malicious domain ratio is also critical to simulate the real-world scheme where approximately 99% of the traffic is devoted to benign. In this paper, we generate and release a large DNS features dataset of 400,000 benign and 13,011 malicious samples processed from a million benign and 51,453 known-malicious domains from publicly available datasets. The malicious samples span between three categories of spam, phishing, and malware. Our dataset, namely CIC-Bell-DNS2021 replicates the real-world scenarios with frequent benign traffic and diverse malicious domain types. We train and validate a classification model that, unlike previous works that focus on binary detection, detects the type of the attack, i.e., spam, phishing, and malware. Classification performance of various ML algorithms on our generated dataset proves the effectiveness of our model, where we achieved the best results for $k$ -Nearest Neighbors $k$ -NN) with 94.8% and 99.4% F1-Score for balanced data ratio (60/40%) and imbalanced data ratio (97/3%), respectively. Finally, we have gone through feature evaluation using information gain analysis to get the merits of each feature in each category, proving the third party features as the most influential one among the top 13 features. keywords- Malicious Domain, DNS, Feature Engineering, Lexical, Statistical, Third Party, Classification
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
空空伊发布了新的文献求助10
刚刚
AaronW完成签到,获得积分10
2秒前
提拉米苏发布了新的文献求助30
4秒前
华仔应助高挑的板凳采纳,获得10
4秒前
祁连山的熊猫完成签到 ,获得积分0
4秒前
科研通AI6.1应助彼岸花开采纳,获得50
5秒前
科研通AI6.2应助Sue@00采纳,获得10
6秒前
哇咔咔完成签到 ,获得积分10
7秒前
hey754发布了新的文献求助10
7秒前
叫我益达完成签到,获得积分10
8秒前
仲夏夜之梦完成签到,获得积分10
8秒前
刘婉敏完成签到 ,获得积分10
9秒前
喵喵帮咩咩写论文完成签到 ,获得积分10
11秒前
咩呜关注了科研通微信公众号
12秒前
代秋发布了新的文献求助10
12秒前
淡淡的小松鼠完成签到,获得积分10
12秒前
14秒前
14秒前
耶耶完成签到,获得积分10
15秒前
kenti2023完成签到 ,获得积分0
16秒前
思源应助Costing采纳,获得10
16秒前
17秒前
温暖眼神完成签到,获得积分10
17秒前
打打应助淡淡的小松鼠采纳,获得10
18秒前
斯文败类应助zhangfan采纳,获得10
18秒前
小丸子完成签到 ,获得积分10
19秒前
jimmylafs发布了新的文献求助10
19秒前
20秒前
张子烜发布了新的文献求助10
20秒前
安心完成签到 ,获得积分10
21秒前
小菀儿完成签到 ,获得积分10
21秒前
斯文无敌完成签到,获得积分10
21秒前
善学以致用应助烤红薯采纳,获得10
21秒前
焦一丹完成签到 ,获得积分10
22秒前
胖丁完成签到,获得积分10
22秒前
华仔应助Xue_wenqiang采纳,获得30
23秒前
24秒前
依山观澜完成签到,获得积分10
24秒前
26秒前
小鱼同学发布了新的文献求助10
27秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Eco-Evo-Devo: The Environmental Regulation of Development, Health, and Evolution 900
Signals, Systems, and Signal Processing 510
Discrete-Time Signals and Systems 510
Lloyd's Register of Shipping's Approach to the Control of Incidents of Brittle Fracture in Ship Structures 500
THC vs. the Best: Benchmarking Turmeric's Powerhouse against Leading Cosmetic Actives 500
培训师成长修炼实操手册(落地版) 400
热门求助领域 (近24小时)
化学 材料科学 生物 医学 工程类 计算机科学 有机化学 物理 生物化学 纳米技术 复合材料 内科学 化学工程 人工智能 催化作用 遗传学 数学 基因 量子力学 物理化学
热门帖子
关注 科研通微信公众号,转发送积分 5926504
求助须知:如何正确求助?哪些是违规求助? 6955691
关于积分的说明 15831647
捐赠科研通 5054463
什么是DOI,文献DOI怎么找? 2719351
邀请新用户注册赠送积分活动 1674775
关于科研通互助平台的介绍 1608688