Detecting Malicious Domains Using Statistical Internationalized Domain Name Features in Top Level Domains

11/15/2022
by   Alshaima Almarzooqi, et al.
0

The Domain Name System (DNS) is a core Internet service that translates domain names into IP addresses. It is a distributed database and protocol with many known weaknesses that subject to countless attacks including spoofing attacks, botnets, and domain name registrations. Still, the debate between security and privacy is continuing, that is DNS over TLS or HTTP, and the lack of adoption of DNS security extensions, put users at risk. Consequently, the security of domain names and characterizing malicious websites is becoming a priority. This paper analyzes the difference between the malicious and the normal domain names and uses Python to extract various malicious DNS identifying characteristics. In addition, the paper contributes two categories of features that suppers Internationalized Domain Names and scans domain system using five tools to give it a rating. The overall accuracy of the Random Forest Classifier was 95.6

READ FULL TEXT
research
12/17/2022

Study on Domain Name System (DNS) Abuse: Technical Report

A safe and secure Domain Name System (DNS) is of paramount importance fo...
research
08/14/2020

Privacy Preserving Passive DNS

The Domain Name System (DNS) was created to resolve the IP addresses of ...
research
05/16/2018

Investigating the Agility Bias in DNS Graph Mining

The concept of agile domain name system (DNS) refers to dynamic and rapi...
research
09/21/2020

Domain-Embeddings Based DGA Detection with Incremental Training Method

DGA-based botnet, which uses Domain Generation Algorithms (DGAs) to evad...
research
05/04/2022

Early Detection of Spam Domains with Passive DNS and SPF

Spam domains are sources of unsolicited mails and one of the primary veh...
research
04/02/2020

Typosquatting for Fun and Profit: Cross-Country Analysis of Pop-Up Scam

Today, many different types of scams can be found on the internet. Onlin...
research
07/14/2022

A DNS Tunnel Sliding Window Differential Detection Method Based on Normal Distribution Reasonable Range Filtering

A covert attack method often used by APT organizations is the DNS tunnel...

Please sign up or login with your details

Forgot password? Click here to reset