Logotipo do repositório
 

Publicação:
Multiclass Classification of Malicious Domains Using Passive DNS with XGBoost: (Work in Progress)

dc.contributor.authorDa Silva, Leandro Marcos [UNESP]
dc.contributor.authorSilveira, Marcos Rogerio [UNESP]
dc.contributor.authorCansian, Adriano Mauro [UNESP]
dc.contributor.authorKobayashi, Hugo Koji
dc.contributor.institutionUniversidade Estadual Paulista (Unesp)
dc.contributor.institutionBrazilian Network Information Center
dc.date.accessioned2021-06-25T11:10:33Z
dc.date.available2021-06-25T11:10:33Z
dc.date.issued2020-11-24
dc.description.abstractThe Domain Name System (DNS) protocol provides the mapping between hostnames and Internet Protocol addresses and vice versa. However, attackers use the DNS structure to register malicious domains to engage in malicious activities. One way to mitigate these domains is to use blocklists, but there is considerable time in human detection and insertion into lists. Thus, there are works aimed at detecting domains in an automated way applying machine learning techniques. Given this scenario, the present work presents an analysis of blocklists to identify patterns in malicious domains, where it was concluded that Top Level Domains might be associated with the maliciousness of a domain. After that, a system overview for the multiclass classification of malicious domains using passive DNS is proposed. The system has an exclusive character, because it is the first to use a multiclass approach to indicate the threat present in the malicious domain, and yet, it uses XGBoost and techniques to balance the data.en
dc.description.affiliationSao Paulo State University (UNESP)
dc.description.affiliationNICBR Brazilian Network Information Center
dc.description.affiliationUnespSao Paulo State University (UNESP)
dc.identifierhttp://dx.doi.org/10.1109/NCA51143.2020.9306705
dc.identifier.citation2020 IEEE 19th International Symposium on Network Computing and Applications, NCA 2020.
dc.identifier.doi10.1109/NCA51143.2020.9306705
dc.identifier.scopus2-s2.0-85099725248
dc.identifier.urihttp://hdl.handle.net/11449/208338
dc.language.isoeng
dc.relation.ispartof2020 IEEE 19th International Symposium on Network Computing and Applications, NCA 2020
dc.sourceScopus
dc.subjectDomain Name System
dc.subjectMalicious Domain
dc.subjectMulticlass Classification
dc.subjectPassive DNS
dc.subjectXGBoost
dc.titleMulticlass Classification of Malicious Domains Using Passive DNS with XGBoost: (Work in Progress)en
dc.typeTrabalho apresentado em evento
dspace.entity.typePublication
unesp.campusUniversidade Estadual Paulista (UNESP), Instituto de Biociências Letras e Ciências Exatas, São José do Rio Pretopt
unesp.departmentEngenharia Mecânica - FEBpt
unesp.departmentCiências da Computação e Estatística - IBILCEpt

Arquivos