{"title":"CLEAN:基于被动DNS流量检测良性域名的一种方法","authors":"Chunyu Han, Yongzheng Zhang","doi":"10.1109/ICCSNT.2017.8343715","DOIUrl":null,"url":null,"abstract":"Domain name plays a crucial role on the Internet. Therefore, more and more malicious behavior had been conducted by using the domain name, such as spam, botnet, phishing and the like. Thus, lots of research have been done for detecting these malicious domain names. Nevertheless, the effort focused on benign domain names is little. It is obvious that finding more benign domain names accurately is very helpful for detecting malicious domain names. In this paper, we analyze a great number of domain names and propose a method, CLEAN(CLassifier of bEnign domAin Names), for discovering benign domain names from plenty of domain names on the passive DNS traffic. Eventually, we conducted the experiment to check the effect. The result showed the recall rate is 82.1% and accuracy rate is 92.2%.","PeriodicalId":163433,"journal":{"name":"2017 6th International Conference on Computer Science and Network Technology (ICCSNT)","volume":"28 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":"{\"title\":\"CLEAN : An approach for detecting benign domain names based on passive DNS traffic\",\"authors\":\"Chunyu Han, Yongzheng Zhang\",\"doi\":\"10.1109/ICCSNT.2017.8343715\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Domain name plays a crucial role on the Internet. Therefore, more and more malicious behavior had been conducted by using the domain name, such as spam, botnet, phishing and the like. Thus, lots of research have been done for detecting these malicious domain names. Nevertheless, the effort focused on benign domain names is little. It is obvious that finding more benign domain names accurately is very helpful for detecting malicious domain names. In this paper, we analyze a great number of domain names and propose a method, CLEAN(CLassifier of bEnign domAin Names), for discovering benign domain names from plenty of domain names on the passive DNS traffic. Eventually, we conducted the experiment to check the effect. The result showed the recall rate is 82.1% and accuracy rate is 92.2%.\",\"PeriodicalId\":163433,\"journal\":{\"name\":\"2017 6th International Conference on Computer Science and Network Technology (ICCSNT)\",\"volume\":\"28 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2017-10-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"1\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2017 6th International Conference on Computer Science and Network Technology (ICCSNT)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICCSNT.2017.8343715\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2017 6th International Conference on Computer Science and Network Technology (ICCSNT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICCSNT.2017.8343715","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
CLEAN : An approach for detecting benign domain names based on passive DNS traffic
Domain name plays a crucial role on the Internet. Therefore, more and more malicious behavior had been conducted by using the domain name, such as spam, botnet, phishing and the like. Thus, lots of research have been done for detecting these malicious domain names. Nevertheless, the effort focused on benign domain names is little. It is obvious that finding more benign domain names accurately is very helpful for detecting malicious domain names. In this paper, we analyze a great number of domain names and propose a method, CLEAN(CLassifier of bEnign domAin Names), for discovering benign domain names from plenty of domain names on the passive DNS traffic. Eventually, we conducted the experiment to check the effect. The result showed the recall rate is 82.1% and accuracy rate is 92.2%.