首页> 外文会议>International conference on information and communications security >MalHunter: Performing a Timely Detection on Malicious Domains via a Single DNS Query
【24h】

MalHunter: Performing a Timely Detection on Malicious Domains via a Single DNS Query

机译:MalHunter:通过单个DNS查询对恶意域进行及时检测

获取原文

摘要

Domain names have been abused for illicit online activities for decades. A wealth of effort has been devoted to detect malicious domains in the past. However, these works primarily identify suspicious DNS behaviors (e.g., lookup patterns, resolution graphs) to distinguish legitimate domains from malicious ones. Whereas, these behaviors can only be observed after malicious activity is already underway, thus are often too late to prevent miscreants from reaping benefits of the attacks, delaying detection. In this paper, we propose MalHunter, a timely detection technique that determines a domain's reputation via only a single DNS query. We base it on the insight that miscreants need to host malicious domains on IPs that they control, which makes different malicious domains are commonly hosted on the same IPs and creates intrinsic associations. To capture these inherent associations, we employ a deep neural network architecture based method, thus making it possible for detecting malicious domains via only a single DNS query. We evaluate MalHunter using real-world DNS traffic collected from three large ISP networks in China over two months. Compared to previous approaches, our method significantly reduces the time delay of detection from days or weeks to approximate ten microseconds while maintaining as high detection accuracy.
机译:几十年来,域名已被用于非法在线活动。过去,人们已经付出了巨大的努力来检测恶意域。但是,这些作品主要是识别可疑的DNS行为(例如,查找模式,解析图),以区分合法域和恶意域。鉴于这些行为只能在恶意活动已经进行之后才能观察到,因此通常为时已晚,无法防止恶意分子从攻击中获得好处,从而延迟了检测。在本文中,我们提出了MalHunter,这是一种及时的检测技术,它只能通过单个DNS查询来确定域的信誉。我们基于这样的见解,即恶意者需要在他们控制的IP上托管恶意域,这使得不同的恶意域通常托管在同一IP上并创建内部关联。为了捕获这些固有的关联,我们采用了基于深度神经网络架构的方法,从而使得仅通过单个DNS查询即可检测到恶意域。我们使用来自中国三个大型ISP网络在两个月内收集的真实DNS流量来评估MalHunter。与以前的方法相比,我们的方法显着减少了从几天或几周的检测时间延迟到大约十微秒,同时保持了很高的检测精度。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号