Logotipo do repositório
 

Publicação:
Early Identification of Abused Domains in TLD through Passive DNS Applying Machine Learning Techniques

dc.contributor.authorSilva, Leandro Marcos da [UNESP]
dc.contributor.authorSilveira, Marcos Rogério [UNESP]
dc.contributor.authorCansian, Adriano Mauro [UNESP]
dc.contributor.authorKobayashi, Hugo Koji
dc.contributor.institutionUniversidade Estadual Paulista (UNESP)
dc.contributor.institutionBrazilian Network Information Center (NIC.br)
dc.date.accessioned2023-03-01T20:38:25Z
dc.date.available2023-03-01T20:38:25Z
dc.date.issued2022-04-01
dc.description.abstractDNS is vital for the proper functioning of the Internet. However, users use this structure for domain registration and abuse. These domains are used as tools for these users to carry out the most varied attacks. Thus, early detection of abused domains prevents more people from falling into scams. In this work, an approach for identifying abused domains was developed using passive DNS collected from an authoritative DNS server TLD along with the data enriched through geolocation, thus enabling a global view of the domains. Therefore, the system monitors the domain's first seven days of life after its first DNS query, in which two behavior checks are performed, the first with three days and the second with seven days. The generated models apply the machine learning algorithm LightGBM, and because of the unbalanced data, the combination of Cluster Centroids and K-Means SMOTE techniques were used. As a result, it obtained an average AUC of 0.9673 for the three-day model and an average AUC of 0.9674 for the seven-day model. Finally, the validation of three and seven days in a test environment reached a TPR of 0.8656 and 0.8682, respectively. It was noted that the system has a satisfactory performance for the early identification of abused domains and the importance of a TLD to identify these domains.en
dc.description.affiliationSao Paulo State University (UNESP) Department of Computer Science and Statistics (DCCE)
dc.description.affiliationBrazilian Network Information Center (NIC.br)
dc.description.affiliationUnespSao Paulo State University (UNESP) Department of Computer Science and Statistics (DCCE)
dc.format.extent76-85
dc.identifierhttp://dx.doi.org/10.54039/ijcnis.v14i1.5256
dc.identifier.citationInternational Journal of Communication Networks and Information Security, v. 14, n. 1, p. 76-85, 2022.
dc.identifier.doi10.54039/ijcnis.v14i1.5256
dc.identifier.issn2073-607X
dc.identifier.issn2076-0930
dc.identifier.scopus2-s2.0-85129288286
dc.identifier.urihttp://hdl.handle.net/11449/240917
dc.language.isoeng
dc.relation.ispartofInternational Journal of Communication Networks and Information Security
dc.sourceScopus
dc.subjectabused domains in TLD
dc.subjectcybersecurity
dc.subjectdata imbalanced
dc.subjectmachine learning algorithms
dc.subjectpassive DNS
dc.titleEarly Identification of Abused Domains in TLD through Passive DNS Applying Machine Learning Techniquesen
dc.typeArtigo
dspace.entity.typePublication
unesp.campusUniversidade Estadual Paulista (UNESP), Instituto de Biociências Letras e Ciências Exatas, São José do Rio Pretopt
unesp.departmentCiências da Computação e Estatística - IBILCEpt

Arquivos