Adopting Machine Learning to Support the Detection of Malicious Domain Names

Fernanda Magalhães, J. Magalhães
{"title":"Adopting Machine Learning to Support the Detection of Malicious Domain Names","authors":"Fernanda Magalhães, J. Magalhães","doi":"10.1109/IOTSMS52051.2020.9340159","DOIUrl":null,"url":null,"abstract":"Nowadays there are many Domain Name System (DNS) firewall solutions to prevent users to access malicious domains. These can provide real time protection and block illegitimate communications. Most of these solutions are based on known malicious domain names lists (blocklists) that are being constantly updated. However, this way, it is only possible to block malicious communications for known malicious domains, leaving out many others that are malicious but have not yet been updated in the blocklists. In this paper we present a study on the usefulness of adopting machine learning to detect malicious domain names. From a large set of domain names classified in-advance as malicious or benign an enriched dataset with multiple features was created and analyzed. The exploratory analysis and the data preparation tasks were carried out and the results achieved by different machine learning classification algorithms. Depending on the classification algorithm, the accuracy results varied between 75% and 92% and the classification time ranged between 2.77 seconds and 5320 seconds. These results are interesting in that they make it possible to classify a new domain as malicious or not in a short time and with good hit rate.","PeriodicalId":147136,"journal":{"name":"2020 7th International Conference on Internet of Things: Systems, Management and Security (IOTSMS)","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-12-14","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 7th International Conference on Internet of Things: Systems, Management and Security (IOTSMS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/IOTSMS52051.2020.9340159","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

Nowadays there are many Domain Name System (DNS) firewall solutions to prevent users to access malicious domains. These can provide real time protection and block illegitimate communications. Most of these solutions are based on known malicious domain names lists (blocklists) that are being constantly updated. However, this way, it is only possible to block malicious communications for known malicious domains, leaving out many others that are malicious but have not yet been updated in the blocklists. In this paper we present a study on the usefulness of adopting machine learning to detect malicious domain names. From a large set of domain names classified in-advance as malicious or benign an enriched dataset with multiple features was created and analyzed. The exploratory analysis and the data preparation tasks were carried out and the results achieved by different machine learning classification algorithms. Depending on the classification algorithm, the accuracy results varied between 75% and 92% and the classification time ranged between 2.77 seconds and 5320 seconds. These results are interesting in that they make it possible to classify a new domain as malicious or not in a short time and with good hit rate.
采用机器学习支持恶意域名检测
目前有很多域名系统(DNS)防火墙解决方案来防止用户访问恶意域名。这些可以提供实时保护并阻止非法通信。大多数这些解决方案是基于已知的恶意域名列表(阻止列表),这些列表正在不断更新。然而,这种方式只能阻止已知恶意域的恶意通信,而忽略了许多其他恶意但尚未在阻止列表中更新的恶意通信。在本文中,我们对采用机器学习来检测恶意域名的有效性进行了研究。从预先分类为恶意或良性的大量域名中创建并分析了具有多个特征的丰富数据集。进行探索性分析和数据准备任务,并通过不同的机器学习分类算法获得结果。根据不同的分类算法,准确率在75% ~ 92%之间,分类时间在2.77 ~ 5320秒之间。这些结果很有趣,因为它们可以在短时间内以良好的命中率将新域分类为恶意或非恶意。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信