首页    期刊浏览 2024年11月27日 星期三
登录注册

文章基本信息

  • 标题:Detection of Algorithmically Generated Malicious Domain
  • 本地全文:下载
  • 作者:Enoch Agyepong ; William J. Buchanan ; Kevin Jones
  • 期刊名称:Computer Science & Information Technology
  • 电子版ISSN:2231-5403
  • 出版年度:2018
  • 卷号:8
  • 期号:8
  • 页码:13-32
  • DOI:10.5121/csit.2018.80802
  • 出版社:Academy & Industry Research Collaboration Center (AIRCC)
  • 摘要:In recent years, many malware writers have relied on Dynamic Domain Name Services (DDNS)to maintain their Command and Control (C&C) network infrastructure to ensure a persistencepresence on a compromised host. Amongst the various DDNS techniques, Domain GenerationAlgorithm (DGA) is often perceived as the most difficult to detect using traditional methods.This paper presents an approach for detecting DGA using frequency analysis of the characterdistribution and the weighted scores of the domain names. The approach’s feasibility isdemonstrated using a range of legitimate domains and a number of malicious algorithmicallygenerateddomain names. Findings from this study show that domain names made up of Englishcharacters “a-z” achieving a weighted score of < 45 are often associated with DGA. When aweighted score of < 45 is applied to the Alexa one million list of domain names, only 15% of thedomain names were treated as non-human generated.
  • 关键词:Domain Generated Algorithm; malicious domain names; Domain Name Frequency Analysis &;malicious DNS
国家哲学社会科学文献中心版权所有