{"title":"CLEAN : An approach for detecting benign domain names based on passive DNS traffic","authors":"Chunyu Han, Yongzheng Zhang","doi":"10.1109/ICCSNT.2017.8343715","DOIUrl":null,"url":null,"abstract":"Domain name plays a crucial role on the Internet. Therefore, more and more malicious behavior had been conducted by using the domain name, such as spam, botnet, phishing and the like. Thus, lots of research have been done for detecting these malicious domain names. Nevertheless, the effort focused on benign domain names is little. It is obvious that finding more benign domain names accurately is very helpful for detecting malicious domain names. In this paper, we analyze a great number of domain names and propose a method, CLEAN(CLassifier of bEnign domAin Names), for discovering benign domain names from plenty of domain names on the passive DNS traffic. Eventually, we conducted the experiment to check the effect. The result showed the recall rate is 82.1% and accuracy rate is 92.2%.","PeriodicalId":163433,"journal":{"name":"2017 6th International Conference on Computer Science and Network Technology (ICCSNT)","volume":"28 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2017 6th International Conference on Computer Science and Network Technology (ICCSNT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICCSNT.2017.8343715","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1
Abstract
Domain name plays a crucial role on the Internet. Therefore, more and more malicious behavior had been conducted by using the domain name, such as spam, botnet, phishing and the like. Thus, lots of research have been done for detecting these malicious domain names. Nevertheless, the effort focused on benign domain names is little. It is obvious that finding more benign domain names accurately is very helpful for detecting malicious domain names. In this paper, we analyze a great number of domain names and propose a method, CLEAN(CLassifier of bEnign domAin Names), for discovering benign domain names from plenty of domain names on the passive DNS traffic. Eventually, we conducted the experiment to check the effect. The result showed the recall rate is 82.1% and accuracy rate is 92.2%.