Classifying Malicious Domains using DNS Traffic Analysis

网络钓鱼 恶意软件 僵尸网络 计算机科学 域名系统 计算机安全 领域(数学分析) 审查 互联网 黑名单 域名 万维网 数学 数学分析
作者
Samaneh Mahdavifar,Nasim Maleki,Arash Habibi Lashkari,Matt Broda,Amir H. Razavi
标识
DOI:10.1109/dasc-picom-cbdcom-cyberscitech52372.2021.00024
摘要

Malicious domains are one of the major threats that have jeopardized the viability of the Internet over the years. Threat actors usually abuse the Domain Name System (DNS) to lure users to be victims of malicious domains hosting drive-by-download malware, botnets, phishing websites, or spam messages. Each year, many large corporations are impacted by these threats, resulting in huge financial losses in a single attack. Thus, detecting and classifying a malicious domain in a timely manner is essential. Previously, filtering the domains against blacklists was the only way to detect malicious domains, however, this approach was unable to detect newly generated domains. Recently, Machine Learning (ML) techniques have helped to enhance the detection capability of domain vetting systems. A solid feature engineering mechanism plays a pivotal role in boosting the performance of any ML model. Therefore, we have extracted effective and practical features from DNS traffic categorizing them into three groups of lexical-based, DNS statistical-based, and third party-based features. Third party features are biographical information about a specific domain extracted from third party APIs. The benign to malicious domain ratio is also critical to simulate the real-world scheme where approximately 99% of the traffic is devoted to benign. In this paper, we generate and release a large DNS features dataset of 400,000 benign and 13,011 malicious samples processed from a million benign and 51,453 known-malicious domains from publicly available datasets. The malicious samples span between three categories of spam, phishing, and malware. Our dataset, namely CIC-Bell-DNS2021 replicates the real-world scenarios with frequent benign traffic and diverse malicious domain types. We train and validate a classification model that, unlike previous works that focus on binary detection, detects the type of the attack, i.e., spam, phishing, and malware. Classification performance of various ML algorithms on our generated dataset proves the effectiveness of our model, where we achieved the best results for $k$ -Nearest Neighbors $k$ -NN) with 94.8% and 99.4% F1-Score for balanced data ratio (60/40%) and imbalanced data ratio (97/3%), respectively. Finally, we have gone through feature evaluation using information gain analysis to get the merits of each feature in each category, proving the third party features as the most influential one among the top 13 features. keywords- Malicious Domain, DNS, Feature Engineering, Lexical, Statistical, Third Party, Classification
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
怀石逾沙发布了新的文献求助10
刚刚
情怀应助蓝天采纳,获得50
1秒前
BENRONG发布了新的文献求助10
1秒前
Linly完成签到,获得积分10
1秒前
杨海发布了新的文献求助10
1秒前
2秒前
浮梦发布了新的文献求助10
2秒前
潇潇发布了新的文献求助10
3秒前
3秒前
过儿发布了新的文献求助10
3秒前
酒巷发布了新的文献求助10
3秒前
BLAZe发布了新的文献求助10
4秒前
6秒前
cdercder应助纯真的觅儿采纳,获得10
7秒前
mu完成签到,获得积分10
7秒前
ira发布了新的文献求助10
7秒前
GWB完成签到,获得积分10
7秒前
Orange应助千秋竞岁采纳,获得10
8秒前
9秒前
9秒前
浮梦完成签到,获得积分10
9秒前
香蕉笑卉发布了新的文献求助30
11秒前
12秒前
12秒前
heng发布了新的文献求助10
12秒前
wok有蚊子完成签到 ,获得积分20
12秒前
笑点低的谷槐关注了科研通微信公众号
12秒前
cdercder应助暴走章鱼采纳,获得10
13秒前
13秒前
酷波er应助盒子采纳,获得30
13秒前
低糖低脂肪完成签到,获得积分10
14秒前
14秒前
lll完成签到,获得积分10
14秒前
CodeCraft应助wooahh采纳,获得10
15秒前
大模型应助球球采纳,获得10
15秒前
完美的寄翠完成签到,获得积分10
16秒前
SHI完成签到,获得积分10
17秒前
惊蛰完成签到,获得积分10
17秒前
17秒前
18秒前
高分求助中
液晶指向矢仿真分析数据集 6666
GL 2 A method for assessing the in-place cleanability of food processing equipment, Fourth Edition, December 2023 3000
Annie Ernaux: De la perte au corps glorieux 600
Petrology and Plate Tectonics 500
Writing Systems 500
Media Today Mass Communication in a Converging World 9th Edition 400
Understanding Modeling and Simulation of Polymerization Reactions 400
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 物理 内科学 复合材料 催化作用 物理化学 光电子学 电极 细胞生物学 基因 无机化学
热门帖子
关注 科研通微信公众号,转发送积分 6843890
求助须知:如何正确求助?哪些是违规求助? 8551584
关于积分的说明 18193801
捐赠科研通 6195969
什么是DOI,文献DOI怎么找? 3041296
关于科研通互助平台的介绍 2032640
邀请新用户注册赠送积分活动 2018784