Malicious Domain Names Detection Algorithm Based on N-Gram
Autor: | Xiangyan Zeng, Zhao Hong, Guangbin Bao, Chang Zhaobin |
---|---|
Rok vydání: | 2019 |
Předmět: |
Article Subject
Computer Networks and Communications Computer science business.industry 020206 networking & telecommunications 02 engineering and technology computer.software_genre Internet security lcsh:QA75.5-76.95 Substring Domain (software engineering) Set (abstract data type) n-gram 0202 electrical engineering electronic engineering information engineering Malware 020201 artificial intelligence & image processing lcsh:Electronic computers. Computer science False positive rate business computer Algorithm Time complexity Information Systems |
Zdroj: | Journal of Computer Networks and Communications, Vol 2019 (2019) |
ISSN: | 2090-715X 2090-7141 |
Popis: | Malicious domain name attacks have become a serious issue for Internet security. In this study, a malicious domain names detection algorithm based on N-Gram is proposed. The top 100,000 domain names in Alexa 2013 are used in the N-Gram method. Each domain name excluding the top-level domain is segmented into substrings according to its domain level with the lengths of 3, 4, 5, 6, and 7. The substring set of the 100,000 domain names is established, and the weight value of a substring is calculated according to its occurrence number in the substring set. To detect a malicious attack, the domain name is also segmented by the N-Gram method and its reputation value is calculated based on the weight values of its substrings. Finally, the judgment of whether the domain name is malicious is made by thresholding. In the experiments on Alexa 2017 and Malware domain list, the proposed detection algorithm yielded an accuracy rate of 94.04%, a false negative rate of 7.42%, and a false positive rate of 6.14%. The time complexity is lower than other popular malicious domain names detection algorithms. |
Databáze: | OpenAIRE |
Externí odkaz: |