2017
DOI: 10.1007/s10207-017-0396-7
|View full text |Cite
|
Sign up to set email alerts
|

DomainProfiler: toward accurate and early discovery of domain names abused in future

Abstract: Domain names are at the base of today's cyber-attacks. Attackers abuse the domain name system (DNS) to mystify their attack ecosystems; they systematically generate a huge volume of distinct domain names to make it infeasible for blacklisting approaches to keep up with newly generated malicious domain names. To solve this problem, we propose DomainProfiler for discovering malicious domain names that are likely to be abused in future. The key idea with our system is to exploit temporal variation patterns (TVPs)… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1

Citation Types

0
4
0

Year Published

2019
2019
2024
2024

Publication Types

Select...
6
1
1

Relationship

1
7

Authors

Journals

citations
Cited by 10 publications
(4 citation statements)
references
References 25 publications
0
4
0
Order By: Relevance
“…Of the 22 ML-based studies in our literature review, five studies used a combination of context-free and context-aware features [18,19,28,30,31], and two studies used contextaware features only [14,20], as indicated in Table 1.…”
Section: Context-aware Featuresmentioning
confidence: 99%
See 1 more Smart Citation
“…Of the 22 ML-based studies in our literature review, five studies used a combination of context-free and context-aware features [18,19,28,30,31], and two studies used contextaware features only [14,20], as indicated in Table 1.…”
Section: Context-aware Featuresmentioning
confidence: 99%
“…Chiba et al [14] used 55 context-aware features: 20 features reflect how and when a domain name is included in evolving lists of popular and malicious domain names in a certain time window; 18 features consider information from BGP prefixes, ASN, and IP address registration corresponding to the related IP addresses of a domain name; eight features consider relations between domain names of which IP addresses are in the same ASN (so called rDomains). They also use nine features that relate to domain names in rDomains.…”
Section: Context-aware Featuresmentioning
confidence: 99%
“…Specifically, in October 2013, many new gTLDs, such as .xyz or .top, were introduced. Consequently, the number of available public suffixes is rapidly increasing and these new gTLDs are known to have been used in attacks [17]. Hence, this step enables us to expand the range of detectable homograph IDNs.…”
Section: Step 1: Separating the Domain Namesmentioning
confidence: 99%
“…And, seventh, it is reproducible: we describe it in detail and have released its source code [34]. Moreover, since we released AVCLASS in July 2016, it has became a popular tool, and has been used by multiple research groups [35][36][37][38][39][40][41][42][43][44][45][46]. Among these works, Lever et al [47], further demonstrated the scalability of AVCLASS by applying it 23.9M samples.…”
Section: Pup and Malware Labelingmentioning
confidence: 99%