作者
Daiki Chiba, Takeshi Yagi, Mitsuaki Akiyama, Toshiki Shibahara, Takeshi Yada, Tatsuya Mori, Shigeki Goto
发表日期
2016/6/28
研讨会论文
2016 46th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
页码范围
491-502
出版商
IEEE
简介
Cyber attackers abuse the domain name system (DNS) to mystify their attack ecosystems, they systematically generate a huge volume of distinct domain names to make it infeasible for blacklisting approaches to keep up with newly generated malicious domain names. As a solution to this problem, we propose a system for discovering malicious domain names that will likely be abused in future. The key idea with our system is to exploit temporal variation patterns (TVPs) of domain names. The TVPs of domain names include information about how and when a domain name has been listed in legitimate/popular and/or malicious domain name lists. On the basis of this idea, our system actively collects DNS logs, analyzes their TVPs, and predicts whether a given domain name will be used for malicious purposes. Our evaluation revealed that our system can predict malicious domain names 220 days beforehand with a …
引用总数
20172018201920202021202220232024379911965
学术搜索中的文章
D Chiba, T Yagi, M Akiyama, T Shibahara, T Yada… - 2016 46th Annual IEEE/IFIP International Conference …, 2016