HinDom: A Robust Malicious Domain Detection System based on Heterogeneous Information Network with Transductive Classification

09/04/2019
by   Xiaoqing Sun, et al.
0

Domain name system (DNS) is a crucial part of the Internet, yet has been widely exploited by cyber attackers. Apart from making static methods like blacklists or sinkholes infeasible, some weasel attackers can even bypass detection systems with machine learning based classifiers. As a solution to this problem, we propose a robust domain detection system named HinDom. Instead of relying on manually selected features, HinDom models the DNS scene as a Heterogeneous Information Network (HIN) consist of clients, domains, IP addresses and their diverse relationships. Besides, the metapath-based transductive classification method enables HinDom to detect malicious domains with only a small fraction of labeled samples. So far as we know, this is the first work to apply HIN in DNS analysis. We build a prototype of HinDom and evaluate it in CERNET2 and TUNET. The results reveal that HinDom is accurate, robust and can identify previously unknown malicious domains.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
06/21/2019

Joint Detection of Malicious Domains and Infected Clients

Detection of malware-infected computers and detection of malicious web d...
research
10/30/2021

Uncovering IP Address Hosting Types Behind Malicious Websites

Hundreds of thousands of malicious domains are created everyday. These m...
research
06/02/2020

Less is More: Robust and Novel Features for Malicious Domain Detection

Malicious domains are increasingly common and pose a severe cybersecurit...
research
03/12/2020

Inline Detection of DGA Domains Using Side Information

Malware applications typically use a command and control (C C) server ...
research
06/28/2021

Realtime Robust Malicious Traffic Detection via Frequency Domain Analysis

Machine learning (ML) based malicious traffic detection is an emerging s...
research
07/25/2023

The GANfather: Controllable generation of malicious activity to improve defence systems

Machine learning methods to aid defence systems in detecting malicious a...
research
09/03/2022

Phishing URL Detection: A Network-based Approach Robust to Evasion

Many cyberattacks start with disseminating phishing URLs. When clicking ...

Please sign up or login with your details

Forgot password? Click here to reset