Improved Detection of Malicious Domain Names Using Gradient Boosted Machines and Feature Engineering

被引:4
|
作者
Alhogail, Areej [1 ]
Al-Turaiki, Isra [2 ]
机构
[1] King Saud Univ, STCs Artificial Intelligence Chair, Dept Informat Syst, Coll Comp & Informat Sci, Riyadh 11543, Saudi Arabia
[2] King Saud Univ, Informat Technol Dept, Coll Comp & Informat Sci, Riyadh 11543, Saudi Arabia
来源
INFORMATION TECHNOLOGY AND CONTROL | 2022年 / 51卷 / 02期
关键词
malicious domain detection; cyber security; machine learning; host features; lexical features; gradient boosted machines (GBM); deep feature synthesis (DFS);
D O I
10.5755/j01.itc.51.2.30380
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Malicious domain names have been commonly used in recent years to launch different cyber-attacks. There area large number of malicious domains that are registered every day and some of which are only active for brief periods of time. Therefore, the automated malicious domain names detection is needed to provide security for individuals and organisations. As new technologies continue to emerge, the detection of malicious domain names remains a challenging task. In this study, we propose a model to effectively detect malicious domain names. This is done by evaluating the performance of several machine learning algorithms and feature importance measures using a recent DNS dataset. Based on the empirical evaluation, the gradient boosted machines GBM classification with a combination of lexical and host-based features produce the most accurate detection rates of 98.8% accuracy and a low false positive rate of 0.003. In terms of feature importance, measures used in this study agree on the importance of six features, five of which are lexical in nature. Furthermore, to make the best out of these relevant features, we apply automatic feature engineering. Our results show that preprocessing the dataset using deep feature synthesis and then reducing the dimensionality improves the classifications performance as compared to using raw features. The results of this study are then verified using a challenging category of domain names, the domain generation algorithm dataset, and consistent results are obtained.
引用
收藏
页码:313 / 331
页数:19
相关论文
共 50 条
  • [1] Detection of malicious domain names based on an improved hidden Markov model
    Tang, Hengliang
    Dong, Chengang
    [J]. International Journal of Wireless and Mobile Computing, 2019, 16 (01) : 58 - 65
  • [2] Detection of malicious and abusive domain names
    Kidmose, Egon
    Lansing, Erwin
    Brandbyge, Soren
    Pedersen, Jens Myrup
    [J]. 2018 1ST INTERNATIONAL CONFERENCE ON DATA INTELLIGENCE AND SECURITY (ICDIS 2018), 2018, : 49 - 56
  • [3] Malicious Domain Names Detection Algorithm Based on Lexical Analysis and Feature Quantification
    Zhao, Hong
    Chang, Zhaobin
    Wang, Weijie
    Zeng, Xiangyan
    [J]. IEEE ACCESS, 2019, 7 : 128990 - 128999
  • [4] Detecting Malicious Domain Names with Abnormal WHOIS Records Using Feature-Based Rules
    Cheng, Yanan
    Chai, Tingting
    Zhang, Zhaoxin
    Lu, Keyu
    Du, Yuejin
    [J]. COMPUTER JOURNAL, 2022, 65 (09): : 2262 - 2275
  • [5] Detecting Malicious Domain Names with Abnormal WHOIS Records Using Feature-Based Rules
    Cheng, Yanan
    Chai, Tingting
    Zhang, Zhaoxin
    Lu, Keyu
    Du, Yuejin
    [J]. Computer Journal, 2022, 65 (09): : 2262 - 2275
  • [6] Adopting Machine Learning to Support the Detection of Malicious Domain Names
    Magalhaes, Fernanda
    Magalhaes, Joao Paulo
    [J]. 2020 7TH INTERNATIONAL CONFERENCE ON INTERNET OF THINGS: SYSTEMS, MANAGEMENT AND SECURITY (IOTSMS), 2020,
  • [7] A Hybrid Multiclass Classifier Approach for the Detection of Malicious Domain Names Using RNN Model
    Aarthi, B.
    Shafana, N. Jeenath
    Flavia, Judy
    Chelliah, Balika J.
    [J]. COMPUTATIONAL VISION AND BIO-INSPIRED COMPUTING ( ICCVBIC 2021), 2022, 1420 : 471 - 482
  • [8] Detection of algorithmically generated malicious domain names using masked N-grams
    Selvi, Jose
    Rodriguez, Ricardo J.
    Soria-Olivas, Emilio
    [J]. EXPERT SYSTEMS WITH APPLICATIONS, 2019, 124 : 156 - 163
  • [9] Malicious Domain Names Detection Algorithm Based on N-Gram
    Zhao, Hong
    Chang, Zhaobin
    Bao, Guangbin
    Zeng, Xiangyan
    [J]. JOURNAL OF COMPUTER NETWORKS AND COMMUNICATIONS, 2019, 2019
  • [10] Detection of Algorithmically Generated Malicious Domain Names with Feature Fusion of Meaningful Word Segmentation and N-Gram Sequences
    Chen, Shaojie
    Lang, Bo
    Chen, Yikai
    Xie, Chong
    [J]. APPLIED SCIENCES-BASEL, 2023, 13 (07):