A Malicious Domain Detection Method Based on DNS Logs

Siqi Ma, Tong Pang, Rui Cui, DeQuan Yang · 2024

As the Internet continues to expand rapidly, the threat posed by malicious domain names to network security is on the rise. Cybercriminals exploit these domains to launch attacks such as malware infections, phishing scams, DDoS attacks, and botnets, posing a severe risk to both individuals and organizations. In light of this, research into effective methods for detecting malicious domains has become increasingly critical. However, traditional machine learning algorithms and blacklist-based approaches have proven ineffective against the sophisticated Domain Generation Algorithm (DGA) technology used by attackers. Recognizing the importance of DNS (Domain Name System) in detecting and mitigating malicious domains, research has focused on leveraging DNS information for detection. To overcome the limitation of robust feature engineering, This study presents a novel malicious domain detection method that fuses features using an attention mechanism. By integrating IP-domain name features and domain name character features through the attention mechanism, BiLSTM is employed to extract character features, while graph neural networks mine domain name-IP associations from DNS messages. Ultimately, the attention mechanism fuses these two types of features to enhance domain name detection, achieving an impressive accuracy rate of 92.38% on a subset of the CIC-Bell-DNS2021 dataset.

Read the paper · More papers on PaperTik