Telecommunications Science ›› 2020, Vol. 36 ›› Issue (5): 47-55.doi: 10.11959/j.issn.1000-0801.2020150

• Topic: Intelligent and Highly Confrontational Development of Network Security • Previous Articles     Next Articles

Detection of malicious domain name based on a classifier combination

Jiantao SHENG,Maofei CHEN,Dongxin LIU,Laifu WANG,Guoshui SHI,Huamin JIN   

  1. Research Institute of China Telecom Co.,Ltd.,Guangzhou 510630,China
  • Revised:2020-04-22 Online:2020-05-20 Published:2020-05-18

Abstract:

As a fundamental service on the internet,domain name system (DNS) can inevitably be abused by malicious activities.Based on the studies of Botnets and other malwares which made use of the domain generation algorithm (DGA),and researches on current major techniques of malicious domain detection,a malicious domain detection framework based on a classifier combination was proposed.The framework applied the support vector machine (SVM) as its main classifier and combined the naive Bayes classifier (NBC) supportively with some statistical characteristics.Experiment result demonstrates that the framework outperformes current techniques in the offline-training time and the capability of detecting unknow malicious domain families,which satisfies the requirement of internet service provider (ISP) to detect and analyze malicious domainson the internet.

Key words: malicious domain name, Botnet, machine learning, deep learning, classifier combination

CLC Number: 

No Suggested Reading articles found!