• Home
  • Search
  • Extending Black Domain Name List by Using Co-occurrence Relation between DNS Queries
  • Cite Icon48
  • https://doi.org/10.1587/transcom.e95.b.794Copy DOI Icon

Extending Black Domain Name List by Using Co-occurrence Relation between DNS Queries

Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Botnet threats, such as server attacks or sending of spam e-mail, have been increasing. Therefore, infected hosts must be found and their malicious activities mitigated. An effective method for finding infected hosts is to use a blacklist of domain names. When a bot receives attack commands from a Command and Control (C&C) server, it attempts to resolve domain names of C&C servers. We can thus detect infected hosts by finding these that send queries on black domain names. However, we cannot find all infected hosts because of the inaccuracy of blacklists. There are many black domain names, and the lifetimes of these domain names are short; therefore a blacklist cannot cover all black domain names. We thus present a method for finding unknown black domain names by using DNS query data and an existing blacklist of known black domain names. To achieve this, we focus on DNS queries sent by infected hosts. One bot sends several queries on black domain names due to C&C server redundancy. We use the co-occurrence relation of two different domain names to find unknown black domain names and extend the blacklist. If a domain name frequently co-occurs with a known black name, we assume that the domain name is also black. A cross-validation evaluation of the proposed method showed that 91.2% of domain names that are on the validation list scored in the top 1%.

Similar Papers
  • Book Chapter
  • Citations10

AmritaDGA: a comprehensive data set for domain generation algorithms (DGAs) based domain name detection systems and application of deep learning

  • Jul 04, 2019
  • R Vinayakumar +4
  • Conference Article
  • Citations3

Towards active measurement for DNS query behavior of botnets

  • Dec 01, 2012
  • Xiaobo Ma +3
  • PDF
  • Research Article
  • Citations17

A Novel Approach for Detecting DGA-Based Botnets in DNS Queries Using Machine Learning Techniques

  • Jul 05, 2021
  • Journal of Computer Networks and Communications
  • Ali Soleymani +1
  • Book Chapter
  • Citations4

Detection of Algorithmically Generated Domain Names in Botnets

  • Mar 15, 2019
  • Deepak Kumar Vishvakarma +2
  • Research Article
  • Citations30

Unsupervised, low latency anomaly detection of algorithmically generated domain names by generative probabilistic modeling

  • Jan 09, 2014
  • Journal of Advanced Research
  • Jayaram Raghuram +2
  • PDF
  • Research Article
  • Citations60

CharBot: A Simple and Effective Method for Evading DGA Classifiers

  • Jan 01, 2019
  • IEEE Access
  • Jonathan Peck +7
  • Book Chapter
  • Citations2

DNS Flood Attack Mitigation Utilizing Hot-Lists and Stale Content Updates

  • Jan 01, 2019
  • Tasnuva Mahjabin +1
  • Research Article
  • Citations4

A Comprehensive Review of DNS-based Distributed Reflection Denial of Service (DRDoS) Attacks: State-of-the-Art

  • Dec 18, 2022
  • International Journal on Advanced Science Engineering and Information Technology
  • Riyadh Rahef Nuiaa +2
  • Research Article
  • Citations1

DNS ANY Request Cannon Activity in DNS Query Packet Traffic

  • Mar 31, 2014
  • International Journal of Intelligent Engineering and Systems
  • Yuto Takeda +3
  • Research Article
  • Citations6

Detection of malicious domain names based on an improved hidden Markov model

  • Jan 01, 2019
  • International Journal of Wireless and Mobile Computing
  • Hengliang Tang +1
  • Research Article
  • Citations126

Detecting malicious domain names using deep learning approaches at scale

  • Mar 22, 2018
  • Journal of Intelligent & Fuzzy Systems
  • R Vinayakumar +2
  • Book Chapter
  • Citations2

A Clustering Approach for Detecting Auto-generated Botnet Domains

  • Jan 01, 2015
  • Yang Pu +3
  • Research Article

СИСТЕМА ВИЯВЛЕННЯ АНОМАЛІЙ У DNS-ЗАПИТАХ

  • Nov 28, 2024
  • Herald of Khmelnytskyi National University. Technical sciences
  • Юрій Кльоц +3
  • Conference Article
  • Citations3

Detection of Fake Educational Sites Using Fuzzy String Match

  • May 26, 2022
  • Aleksandr N Privalov +1
  • Book Chapter
  • Citations14

Understanding Cross-Channel Abuse with SMS-Spam Support Infrastructure Attribution

  • Jan 01, 2016
  • Bharat Srinivasan +3
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.