Discovering malware based on co-clustering host-domain graphs

Wenqian Zhang, Weina Niu, Jinhong Zhang, Jingqi Li · IOP Conference Series Materials Science and Engineering · 2020

Abstract Malware domain discovery based on passive DNS graph analysis supplements existing methods through DNS request and response data analysis. However, the method does not consider the IP relevance and the high complexity of the suspicious computing process. This paper proposes a malware domain discovery method based on passive DNS and IP relevance. The method calculates reputation score, which combines the shortest path from malicious domains to unknown domain with the malicious IP ratio to determine whether the domain malicious.

Read the paper · More papers on PaperTik