2017
DOI: 10.12783/dtcse/cii2017/17282
|View full text |Cite
|
Sign up to set email alerts
|

Malicious Domain Detection Based on Traffic Similarity

Abstract: Domain name system is an important resource in the Internet. Malicious domain detection techniques are used to find the malicious domains which are designed for malicious behaviors. The paper analyzes the existing malicious domain detection techniques and then proposes a new malicious domain detection technique based on traffic similarity. In this paper, we analyze the public botnet traffic dataset and get the DNS traffic pattern. We apply this pattern to spam as well. In this paper, we use normalized Fréchet … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1

Citation Types

0
1
0

Year Published

2018
2018
2018
2018

Publication Types

Select...
1

Relationship

0
1

Authors

Journals

citations
Cited by 1 publication
(1 citation statement)
references
References 4 publications
(3 reference statements)
0
1
0
Order By: Relevance
“…As shown in Table I, a normal domain name's length is generally shorter than 20, while the length of a DGA domain name is usually longer than that. The DGA domain names listed out in Table I, which are from the Banjiri malware [18], are only as an example in the paper. In fact, the length of some other DGA domain names may be even longer than the length of the names shown in Table I.…”
Section: Properties Analysismentioning
confidence: 99%
“…As shown in Table I, a normal domain name's length is generally shorter than 20, while the length of a DGA domain name is usually longer than that. The DGA domain names listed out in Table I, which are from the Banjiri malware [18], are only as an example in the paper. In fact, the length of some other DGA domain names may be even longer than the length of the names shown in Table I.…”
Section: Properties Analysismentioning
confidence: 99%