Malware Detection using DNS Records and Domain Name Features

被引:9
作者
Al Messabi, Khulood [1 ]
Aldwairi, Monther [1 ,2 ]
Al Yousif, Ayesha [1 ]
Thoban, Anoud [1 ]
Belqasmi, Fatna [1 ]
机构
[1] Zayed Univ, Coll Technol Innovat, Abu Dhabi, U Arab Emirates
[2] Jordan Univ Sci & Technol, Dept Network Engn & Secur, POB 3030, Irbid 22110, Jordan
来源
ICFNDS'18: PROCEEDINGS OF THE 2ND INTERNATIONAL CONFERENCE ON FUTURE NETWORKS AND DISTRIBUTED SYSTEMS | 2018年
关键词
DNS; domain name; malware detection; malicious domains;
D O I
10.1145/3231053.3231082
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
As billions of people depend on Internet application to perform day to day tasks, the prevalent of malwares and online attacks cause a huge loss to global Internet economy prevalent. Domain name system is one of the core components of the Internet, which allows users to type in website names and resolves them to Internet addresses. Several studies proposed using DNS for malware detection, because it is the first step before visiting a specific website. Unfortunately, majority focused on malicious URLs back listing, botnets, top-level-domain, DNS and resolvers. This paper proposes a system to detect malicious domain names, by using eight unique features that accurately identify malicious websites before being visited. We implemented our approach of malicious domain names detection using Python, and experimented with five weeks of real-world data using Weka. The experimental results reports a 77.5% and low false positive rates 22.4%. That is very promising considering the approach detect website based on feature calculated based on URL and without downloading the file.
引用
收藏
页数:7
相关论文
共 24 条
  • [1] Abu Qbeitah M, 2018, INT CONF INFORM COMM, P18, DOI 10.1109/IACS.2018.8355435
  • [2] Al-Duwairi B, 2015, IEEE CONF COMM NETW, P755, DOI 10.1109/CNS.2015.7346920
  • [3] Aldwairi M, 2017, INT J INF SECUR PRIV, V11, P16, DOI 10.4018/IJISP.2017100102
  • [4] Aldwairi M, 2011, J INF ASSUR SECUR, V6, P512
  • [5] Aldwairi M, 2012, 2012 SECOND INTERNATIONAL CONFERENCE ON INNOVATIVE COMPUTING TECHNOLOGY (INTECH), P16, DOI 10.1109/INTECH.2012.6457802
  • [6] AlRoum Khalifa, 2018, EMERGING TECHNOLOGIE, P181
  • [7] [Anonymous], 2011, USENIX
  • [8] [Anonymous], 2005, MORGAN KAUFMANN SERI
  • [9] [Anonymous], 2011, ANN INT C INF THEOR
  • [10] Bilge L, 2011, NDSS 2011 18 ANN NET