Nolan H. Hamilton, Steve McKinney, Eddie Allan, E. Fulp
{"title":"一种有效的多阶段域阴影识别方法","authors":"Nolan H. Hamilton, Steve McKinney, Eddie Allan, E. Fulp","doi":"10.1109/ICC40277.2020.9148945","DOIUrl":null,"url":null,"abstract":"Domain shadowing is the introduction of an illegitimate subdomain under a preexisting legitimate domain. Attackers benefit not only from the inconspicuous nature of these subdomains, but also from the trust associated with the legitimate domain. Classifiers have been used to identify shadowed domains within the DNS namespace; however, most approaches rely on features created from a variety of sources, such as DNS data, Javascript inspection, and HTTP source. Unfortunately, the generation of these features is often highly time-consuming and the features themselves are not always effective in distinguishing current shadowing approaches.This paper introduces a new domain shadowing detection approach that leverages machine learning techniques (classifiers) distributed across multiple stages. Domain names are processed by later stages only if earlier stage findings are inconclusive; therefore, only domain names that require additional scrutiny undergo supplementary processing. Furthermore, features that can be quickly synthesized are located in earlier stages to further reduce detection time. Experimental results using the multi-stage detection system with data from recent domain shadowing campaigns results in 97.7% accuracy and 0.04% false positive rate, with an average classification time of 0.83 seconds per name.","PeriodicalId":106560,"journal":{"name":"ICC 2020 - 2020 IEEE International Conference on Communications (ICC)","volume":"18 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":"{\"title\":\"An Efficient Multi-Stage Approach for Identifying Domain Shadowing\",\"authors\":\"Nolan H. Hamilton, Steve McKinney, Eddie Allan, E. Fulp\",\"doi\":\"10.1109/ICC40277.2020.9148945\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Domain shadowing is the introduction of an illegitimate subdomain under a preexisting legitimate domain. Attackers benefit not only from the inconspicuous nature of these subdomains, but also from the trust associated with the legitimate domain. Classifiers have been used to identify shadowed domains within the DNS namespace; however, most approaches rely on features created from a variety of sources, such as DNS data, Javascript inspection, and HTTP source. Unfortunately, the generation of these features is often highly time-consuming and the features themselves are not always effective in distinguishing current shadowing approaches.This paper introduces a new domain shadowing detection approach that leverages machine learning techniques (classifiers) distributed across multiple stages. Domain names are processed by later stages only if earlier stage findings are inconclusive; therefore, only domain names that require additional scrutiny undergo supplementary processing. Furthermore, features that can be quickly synthesized are located in earlier stages to further reduce detection time. Experimental results using the multi-stage detection system with data from recent domain shadowing campaigns results in 97.7% accuracy and 0.04% false positive rate, with an average classification time of 0.83 seconds per name.\",\"PeriodicalId\":106560,\"journal\":{\"name\":\"ICC 2020 - 2020 IEEE International Conference on Communications (ICC)\",\"volume\":\"18 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2020-06-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"3\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"ICC 2020 - 2020 IEEE International Conference on Communications (ICC)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICC40277.2020.9148945\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"ICC 2020 - 2020 IEEE International Conference on Communications (ICC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICC40277.2020.9148945","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
An Efficient Multi-Stage Approach for Identifying Domain Shadowing
Domain shadowing is the introduction of an illegitimate subdomain under a preexisting legitimate domain. Attackers benefit not only from the inconspicuous nature of these subdomains, but also from the trust associated with the legitimate domain. Classifiers have been used to identify shadowed domains within the DNS namespace; however, most approaches rely on features created from a variety of sources, such as DNS data, Javascript inspection, and HTTP source. Unfortunately, the generation of these features is often highly time-consuming and the features themselves are not always effective in distinguishing current shadowing approaches.This paper introduces a new domain shadowing detection approach that leverages machine learning techniques (classifiers) distributed across multiple stages. Domain names are processed by later stages only if earlier stage findings are inconclusive; therefore, only domain names that require additional scrutiny undergo supplementary processing. Furthermore, features that can be quickly synthesized are located in earlier stages to further reduce detection time. Experimental results using the multi-stage detection system with data from recent domain shadowing campaigns results in 97.7% accuracy and 0.04% false positive rate, with an average classification time of 0.83 seconds per name.