A Multi-feature-based Approach to Malicious Domain Name Identification from DNS Traffic
Chen Zhao, Yongzheng Zhang, Tianning Zang, Yige Chen, Yipeng Wang · 2020
Domain Name System (DNS) is a hierarchical and distributed Internet infrastructure that is responsible for translating human-friendly domain names into Internet addresses. DNS is essential for legitimate Internet users, but it is often abused by Internet-based attackers. To provide better protection for Internet users, we propose Metis, a multi-feature-based approach that identifies malicious domain names from raw DNS response traffic. Metis profiles domain names based on two categories of expressive features, namely resource-based features and name-based features. Using the combination of these novel features, Metis reduces the dependence on massive DNS traces and external intelligence sources (such as Whois information and block lists) while still keeping a high identification precision. We evaluate Metis on real-world DNS traces, and achieve an accuracy of 88.73% and an F-score of 87.68%. Metis improves greatly in the identification ability compared with a most recent work on malicious domain name identifying. Experimental results show that Metis can accurately identify malicious domain names in real-world DNS traffic without the dependence on massive DNS traffic and external intelligence sources.