An Adaptive Malicious Domain Detection Mechanism with DNS Traffic

被引:1
|
作者
ShuoXu [1 ]
Li, ShuQin [1 ]
Meng, Kun [1 ]
Wu, LiJun [1 ]
Ding, Meng [1 ]
机构
[1] Beijing Informat Sci Technol Univ, Joint Lab Sensing & Computat Intelligence, Beijing, Peoples R China
基金
中国国家自然科学基金;
关键词
Botnet; Domain Generation Algorithm; Markov Chain; Self-adaption;
D O I
10.1145/3171592.3171595
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
A domain in Internet represents an address where some services may be provided, and the domain providing malicious service, such as Botnet communication and nonexistent service etc., is called malicious. Once the security system cannot detect and block a family of malicious domain, they will soon flood the whole Internet with request and threaten the network security. Hence, the efficiency and accuracy are always used to evaluate malicious detection models. In this paper, a universal grammar structure detection model with the Markov chain is discussed, which has the benefit of flexibly extracting all kinds of grammar features. Moreover, this paper propose a hybrid malicious domain detection model with techniques of grammar structures and traffic temporal features. The detection backbone is a grammar structure based model which ensure the efficiency, meanwhile traffic temporal feature are timely extracted and used to train the backbone model. Given collected test sample sets and one-month campus network real-time traffic, the proposed model is verified through comparing with enterprise C&C detection tools. The experiment result show that the efficiency, accuracy and scalability all achieve much progress.
引用
收藏
页码:86 / 91
页数:6
相关论文
共 50 条
  • [41] A Cognitive Multifractal Approach to Characterize Complexity of Non-Stationary and Malicious DNS Data Traffic Using Adaptive Sliding Window
    Khan, Muhammad Salman
    Ferens, Ken
    Kinsner, Witold
    [J]. PROCEEDINGS OF 2015 IEEE 14TH INTERNATIONAL CONFERENCE ON COGNITIVE INFORMATICS & COGNITIVE COMPUTING (ICCI*CC), 2015, : 76 - 83
  • [42] Spatio-Temporal Feature Encryption Malicious Traffic Detection via Attention Mechanism
    Wang, Lanting
    Cheng, Jie
    Zhang, Ru
    Chen, Gang
    Wang, Chan
    Pang, Jin
    [J]. 2022 IEEE 10TH INTERNATIONAL CONFERENCE ON INFORMATION, COMMUNICATION AND NETWORKS (ICICN 2022), 2022, : 51 - 56
  • [43] Bot detection by monitoring and grouping domain name server record response queries in DNS traffic
    Vyas, Abhilasha
    Batra, Usha
    [J]. JOURNAL OF INFORMATION & OPTIMIZATION SCIENCES, 2019, 40 (05): : 1143 - 1153
  • [44] Integrated Fuzzy Based Computational Mechanism for the Selection of Effective Malicious Traffic Detection Approach
    Almotiri, Sultan H.
    [J]. IEEE ACCESS, 2021, 9 : 10751 - 10764
  • [45] Detection of DNS Traffic Anomalies in Large Networks
    Cermak, Milan
    Celeda, Pavel
    Vykopal, Jan
    [J]. ADVANCES IN COMMUNICATION NETWORKING, 2014, 8846 : 215 - 226
  • [46] An Effective Malicious Domain Detection Framework
    Cui J.
    Shi L.
    Li J.
    Liu Z.-H.
    Yao Y.-G.
    [J]. Beijing Ligong Daxue Xuebao/Transaction of Beijing Institute of Technology, 2019, 39 (01): : 64 - 67
  • [47] Detection of malicious and abusive domain names
    Kidmose, Egon
    Lansing, Erwin
    Brandbyge, Soren
    Pedersen, Jens Myrup
    [J]. 2018 1ST INTERNATIONAL CONFERENCE ON DATA INTELLIGENCE AND SECURITY (ICDIS 2018), 2018, : 49 - 56
  • [48] Classifying DNS over HTTPS Malicious/Benign Traffic Using Deep Learning Models
    Chougule, Mandar
    Praveen, K.
    Amritha, P. P.
    Viswanathan, Sangeetha
    Ravichandran, K. S.
    Sethumadhavan, M.
    Rahimi, Masoumeh
    Gandomi, Amir H.
    [J]. 2023 10TH INTERNATIONAL CONFERENCE ON SOFT COMPUTING & MACHINE INTELLIGENCE, ISCMI, 2023, : 1 - 5
  • [49] Detection of malicious and low throughput data exfiltration over the DNS protocol
    Nadler, Asaf
    Aminov, Avi
    Shabtai, Asaf
    [J]. COMPUTERS & SECURITY, 2019, 80 : 36 - 53
  • [50] A Deep Learning Based Online Malicious URL and DNS Detection Scheme
    Jiang, Jianguo
    Chen, Jiuming
    Choo, Kim-Kwang Raymond
    Liu, Chao
    Liu, Kunying
    Yu, Min
    Wang, Yongjian
    [J]. SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM 2017, 2018, 238 : 438 - 448