Detection of malicious and abusive domain names

被引:4
|
作者
Kidmose, Egon [1 ,2 ]
Lansing, Erwin [3 ]
Brandbyge, Soren [2 ]
Pedersen, Jens Myrup [1 ]
机构
[1] Aalborg Univ, Dept Elect Syst, Fredrik Bajers Vej 7, DK-9220 Aalborg, Denmark
[2] LEGO Syst AS, DK-7190 Billund, Denmark
[3] DK Hostmaster AS, Kalvebod Brygge 45,3 Sal, DK-1560 Copenhagen V, Denmark
关键词
D O I
10.1109/ICDIS.2018.00015
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The Domain Name System (DNS) is a critical component of the Internet, and as such it is widely relied upon by a large part of the world. Consequently, it can be abused for multiple purposes, with financial gain being perhaps the most obvious, and important. An important countermeasure to such criminal and malicious activity is to identify involved domains, in order to blacklist or otherwise disable them. In this paper we provide the results of studying existing work on detecting malicious domains and analyse the findings. We identify an approach which is promising but has received surprisingly little attention; Pre-registration detection. We identify the following gaps between the problem of domain abuse, and the described state-of-the-art: Existing work on Pre-registration is strictly focused on a single form of abuse, spam, hence it must be explored if Pre-registration detection can be applied to other forms of abuse as well. Existing work, on both Pre-and Post-registration detection, is focused on a few Top-Level domains (TLDs) and Registries, prompting for studies with other TLDs and Registries. There is relevant information, including Registrant-based features, that has not yet been used for Pre-registration detection - which also calls for investigation. Finally, a study of a real-world deployment of Pre-registration detection at a Registry has not yet been presented, despite the potential of the approach. We contribute with an analysis of existing work, by identifying the state-of-the-art, and by identifying important areas of future work.
引用
收藏
页码:49 / 56
页数:8
相关论文
共 50 条
  • [31] Exploration into Gray Area: Toward Efficient Labeling for Detecting Malicious Domain Names
    Fukushi, Naoki
    Chiba, Daiki
    Akiyama, Mitsuaki
    Uchida, Masato
    IEICE TRANSACTIONS ON COMMUNICATIONS, 2020, E103B (04) : 375 - 388
  • [32] A Superficial Analysis Approach for Identifying Malicious Domain Names Generated by DGA Malware
    Satoh, Akihiro
    Fukuda, Yutaka
    Hayashi, Toyohiro
    Kitagata, Gen
    IEEE OPEN JOURNAL OF THE COMMUNICATIONS SOCIETY, 2020, 1 (01): : 1837 - 1849
  • [33] Comprehensible Categorization and Visualization of Orchestrated Malicious Domain Names using Linkage Analysis
    Huang, Shin-Ying
    Chuang, Tzu-Hsien
    Huang, Shi-Meng
    Ban, Tao
    2018 16TH ANNUAL CONFERENCE ON PRIVACY, SECURITY AND TRUST (PST), 2018, : 323 - 324
  • [34] Identifying malicious accounts in blockchains using domain names and associated temporal properties
    Sachan, Rohit Kumar
    Agarwal, Rachit
    Shukla, Sandeep Kumar
    BLOCKCHAIN-RESEARCH AND APPLICATIONS, 2023, 4 (03):
  • [35] An Approach for Identifying Malicious Domain Names Generated by Dictionary-Based DGA Bots
    Satoh, Akihiro
    Nakamura, Yutaka
    Fukuda, Yutaka
    Nobayashi, Daiki
    Ikenaga, Takeshi
    IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2021, E104D (05): : 669 - 672
  • [36] Defending Internet of Things Against Malicious Domain Names using D-FENS
    Spaulding, Jeffrey
    Mohaisen, Aziz
    2018 THIRD IEEE/ACM SYMPOSIUM ON EDGE COMPUTING (SEC), 2018, : 387 - 392
  • [37] Malicious Domain Detection with Machine Learning for Financial Systems
    Gulserliler, Egemen
    Ozgen, Burak
    Bahtiyar, Serif
    2024 7TH INTERNATIONAL BALKAN CONFERENCE ON COMMUNICATIONS AND NETWORKING, BALKANCOM, 2024, : 200 - 205
  • [38] A Unified Learning Approach for Malicious Domain Name Detection
    Wagan, Atif Ali
    Li, Qianmu
    Zaland, Zubair
    Marjan, Shah
    Bozdar, Dadan Khan
    Hussain, Aamir
    Mirza, Aamir Mehmood
    Baryalai, Mehmood
    AXIOMS, 2023, 12 (05)
  • [39] An Adaptive Malicious Domain Detection Mechanism with DNS Traffic
    ShuoXu
    Li, ShuQin
    Meng, Kun
    Wu, LiJun
    Ding, Meng
    PROCEEDINGS OF 2017 VI INTERNATIONAL CONFERENCE ON NETWORK, COMMUNICATION AND COMPUTING (ICNCC 2017), 2017, : 86 - 91
  • [40] Malicious Domain Detection with Heterogeneous Graph Propagation Network
    Hu, Cheng
    Yuan, Fangfang
    Liu, Yanbing
    Cao, Cong
    Zhang, Chunyan
    Tan, Jianlong
    WIRELESS ALGORITHMS, SYSTEMS, AND APPLICATIONS (WASA 2022), PT I, 2022, 13471 : 545 - 556