作者
Leyla Bilge, Sevil Sen, Davide Balzarotti, Engin Kirda, Christopher Kruegel
发表日期
2014/4/1
期刊
ACM Transactions on Information and System Security (TISSEC)
卷号
16
期号
4
页码范围
1-28
出版商
ACM
简介
A wide range of malicious activities rely on the domain name service (DNS) to manage their large, distributed networks of infected machines. As a consequence, the monitoring and analysis of DNS queries has recently been proposed as one of the most promising techniques to detect and blacklist domains involved in malicious activities (e.g., phishing, spam, botnets command-and-control, etc.). EXPOSURE is a system we designed to detect such domains in real time, by applying 15 unique features grouped in four categories.
We conducted a controlled experiment with a large, real-world dataset consisting of billions of DNS requests. The extremely positive results obtained in the tests convinced us to implement our techniques and deploy it as a free, online service. In this article, we present the Exposure system and describe the results and lessons learned from 17 months of its operation. Over this amount of time …
引用总数
20142015201620172018201920202021202220232024413323942426160384210
学术搜索中的文章
L Bilge, S Sen, D Balzarotti, E Kirda, C Kruegel - ACM Transactions on Information and System Security …, 2014