Journal on Communications ›› 2016, Vol. 37 ›› Issue (10): 172-180.doi: 10.11959/j.issn.1000-436x.2016208

• Correspondences • Previous Articles     Next Articles

Anomaly domains detection algorithm based on historical data

Fu-xiang YUAN1,2,Fen-lin LIU1,2,Bin LU1,2,Dao-fu GONG1,2   

  1. 1 School of Cyberspace Security,PLA Information Engineering University,Zhengzhou 450001,China
    2 State Key Laboratory of Mathematical Engineering and Advanced Computing,Zhengzhou 450001,China
  • Online:2016-10-25 Published:2016-10-25
  • Supported by:
    The National Natural Science Foundation of China;The National Natural Science Foundation of China;The National Natural Science Foundation of China;The National Natural Science Foundation of China;The Excellent Youth Foundation of Henan Province of China

Abstract:

An anomaly domains detection algorithm was proposed based on domains’ historical data.Based on statistical differences in historical data of legitimate domains and malicious domains,the proposed algorithm used domains’ lifetime,changes of whois information,whois information integrity,IP changes,domains that share same IP,TTL value,etc,as main parameters and concrete representations of features for classification were given.And on this basis the proposed algorithm constructed SVM classifier for detecting anomaly domains.Features analysis and experimental results show that the algorithm obtains high detection accuracy to unknown domains,especially suitable for detecting long lived malicious domains.

Key words: anomaly domain, domain historical data, feature, detection

No Suggested Reading articles found!