首页> 外文期刊>Journal of computer systems, networks, and communications >Malicious Domain Names Detection Algorithm Based on N-Gram
【24h】

Malicious Domain Names Detection Algorithm Based on N-Gram

机译:基于n-gram的恶意域名检测算法

获取原文
       

摘要

Malicious domain name attacks have become a serious issue for Internet security. In this study, a malicious domain names detection algorithm based on N-Gram is proposed. The top 100,000 domain names in Alexa 2013 are used in the N-Gram method. Each domain name excluding the top-level domain is segmented into substrings according to its domain level with the lengths of 3, 4, 5, 6, and 7. The substring set of the 100,000 domain names is established, and the weight value of a substring is calculated according to its occurrence number in the substring set. To detect a malicious attack, the domain name is also segmented by the N-Gram method and its reputation value is calculated based on the weight values of its substrings. Finally, the judgment of whether the domain name is malicious is made by thresholding. In the experiments on Alexa 2017 and Malware domain list, the proposed detection algorithm yielded an accuracy rate of 94.04%, a false negative rate of 7.42%, and a false positive rate of 6.14%. The time complexity is lower than other popular malicious domain names detection algorithms.
机译:恶意域名攻击已成为互联网安全的严重问题。在本研究中,提出了一种基于N-GR克的恶意域名检测算法。 ALEXA 2013中的前100,000名域名用于N-GRAM方法。排除顶级域的每个域名都根据其域级别分段为3,4,5,6和7的域级别建立了100,000个域名的子字符串集,并且a的权重值根据子字符串集中的其出现数来计算子字符串。为了检测到恶意攻击,域名也被n-gram方法分段,并且基于其子串的权重值计算其声誉值。最后,判断域名是恶意的阈值化。在Alexa 2017和恶意软件域列表的实验中,所提出的检测算法产生了94.04%,7.42%的假负率为6.42&#x0025的精度率。时间复杂性低于其他流行的恶意域名检测算法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号