DyDom: Detecting Malicious Domains with Spatial-Temporal Analysis on Dynamic Graphs
Yixin Li, Xi Luo, Liming Wang, Zhen Xu · 2021
Domain Name System (DNS) has been widely abused by cybercriminals as the critical infrastructure to supply their activities. Thus malicious domains detection is a crucial assignment to combat and mitigate cybercrimes. Existing studies usually recognize malicious domains with blacklists or handcrafted local domain features. However, blacklists and expert-knowledge-based features can be bypassed by attackers with orchestrated techniques, which calls for new detection methods. In this paper, we propose a novel system named DyDom to detect malicious domains intelligently. The key idea of our system is to employ spatial-temporal analysis on domains' behaviors and their temporal variations to catch deep associations among them. In DyDom, we first analyze interactive behaviors among domains, clients and resolve IPs, then generate discrete-time dynamic graphs to model the temporal variations of domains. Further, a classifier based on graph convolutional network (GCN) and gated recurrent unit (GRU) is employed to detect malicious domains by analyzing spatial-temporal associations. As far as we know, DyDom is the first effort to model DNS scene with dynamic graphs and discover malicious domains using spatial-temporal analysis. We develop a prototype of DyDom and evaluate it in real-world data collected from an educational network. The experiment results reveal the effectiveness of our system.