CN105577660B - 基于随机森林的dga域名检测方法 - Google Patents
基于随机森林的dga域名检测方法 Download PDFInfo
- Publication number
- CN105577660B CN105577660B CN201510971299.XA CN201510971299A CN105577660B CN 105577660 B CN105577660 B CN 105577660B CN 201510971299 A CN201510971299 A CN 201510971299A CN 105577660 B CN105577660 B CN 105577660B
- Authority
- CN
- China
- Prior art keywords
- domain name
- feature
- white list
- training
- matrix
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
- 238000007637 random forest analysis Methods 0.000 title claims abstract description 26
- 238000001514 detection method Methods 0.000 title claims abstract description 21
- 238000012549 training Methods 0.000 claims abstract description 37
- 238000000034 method Methods 0.000 claims abstract description 36
- 238000004422 calculation algorithm Methods 0.000 claims abstract description 19
- 239000011159 matrix material Substances 0.000 claims description 25
- 238000003066 decision tree Methods 0.000 claims description 22
- 230000008569 process Effects 0.000 claims description 17
- 238000012546 transfer Methods 0.000 claims description 8
- 239000000284 extract Substances 0.000 claims description 6
- 238000000605 extraction Methods 0.000 claims description 5
- 230000003252 repetitive effect Effects 0.000 claims description 3
- 238000005070 sampling Methods 0.000 claims description 3
- 230000031068 symbiosis, encompassing mutualism through parasitism Effects 0.000 claims description 3
- 230000008901 benefit Effects 0.000 abstract description 6
- 238000010276 construction Methods 0.000 description 5
- 230000006872 improvement Effects 0.000 description 2
- 230000000644 propagated effect Effects 0.000 description 2
- 230000007704 transition Effects 0.000 description 2
- 241001269238 Data Species 0.000 description 1
- 241000700605 Viruses Species 0.000 description 1
- 230000002159 abnormal effect Effects 0.000 description 1
- 238000007630 basic procedure Methods 0.000 description 1
- 230000000694 effects Effects 0.000 description 1
- 238000005516 engineering process Methods 0.000 description 1
- 238000001914 filtration Methods 0.000 description 1
- 230000004907 flux Effects 0.000 description 1
- 230000006870 function Effects 0.000 description 1
- 238000009499 grossing Methods 0.000 description 1
- 238000005259 measurement Methods 0.000 description 1
- 239000000203 mixture Substances 0.000 description 1
- 238000012360 testing method Methods 0.000 description 1
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L61/00—Network arrangements, protocols or services for addressing or naming
- H04L61/45—Network directories; Name-to-address mapping
- H04L61/4505—Network directories; Name-to-address mapping using standardised directories; using standardised directory access protocols
- H04L61/4511—Network directories; Name-to-address mapping using standardised directories; using standardised directory access protocols using domain name system [DNS]
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Information Retrieval, Db Structures And Fs Structures Therefor (AREA)
Abstract
Description
N | N元对及频率 |
1 | “w”、“o”、“y”、“u”、“n” |
2 | “wo”、“oo”、“oy”、“yu”、“un” |
3 | “woo”、“ooy”、“oyu”、“yun” |
4 | “wooy”、“ooyu”、“oyun” |
5 | “wooyu”、“ooyun” |
domain | copytaste | bravonude | singlesnet |
length | 9.00 | 9.00 | 10.00 |
entropy | 2.95 | 3.17 | 2.72 |
gib | 1.00 | 1.00 | 1.00 |
vowel_ratio | 0.33 | 0.44 | 0.30 |
digit_ratio | 0.00 | 0.00 | 0.00 |
repeat_letter | 0.11 | 0.00 | 0.30 |
consec_digit | 0.00 | 0.00 | 0.00 |
consec_consonant | 0.56 | 0.22 | 0.50 |
alexa_grams | 21.56 | 20.23 | 36.97 |
word_grams | 30.31 | 25.13 | 47.22 |
Claims (4)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201510971299.XA CN105577660B (zh) | 2015-12-22 | 2015-12-22 | 基于随机森林的dga域名检测方法 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201510971299.XA CN105577660B (zh) | 2015-12-22 | 2015-12-22 | 基于随机森林的dga域名检测方法 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN105577660A CN105577660A (zh) | 2016-05-11 |
CN105577660B true CN105577660B (zh) | 2019-03-08 |
Family
ID=55887317
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201510971299.XA Active CN105577660B (zh) | 2015-12-22 | 2015-12-22 | 基于随机森林的dga域名检测方法 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN105577660B (zh) |
Families Citing this family (39)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN107590102B (zh) * | 2016-07-06 | 2021-05-04 | 阿里巴巴集团控股有限公司 | 随机森林模型生成方法和装置 |
CN106295887A (zh) * | 2016-08-12 | 2017-01-04 | 辽宁大学 | 基于随机森林的持久种子库预测方法 |
CN107770132B (zh) * | 2016-08-18 | 2021-11-05 | 中兴通讯股份有限公司 | 一种对算法生成域名进行检测的方法及装置 |
CN106230867A (zh) * | 2016-09-29 | 2016-12-14 | 北京知道创宇信息技术有限公司 | 预测域名是否恶意的方法、系统及其模型训练方法、系统 |
US10326736B2 (en) | 2016-11-02 | 2019-06-18 | Cisco Technology, Inc. | Feature-based classification of individual domain queries |
CN107070852B (zh) * | 2016-12-07 | 2020-07-03 | 东软集团股份有限公司 | 网络攻击检测方法和装置 |
CN106713312A (zh) * | 2016-12-21 | 2017-05-24 | 深圳市深信服电子科技有限公司 | 检测非法域名的方法及装置 |
CN106992969A (zh) * | 2017-03-03 | 2017-07-28 | 南京理工大学 | 基于域名字符串统计特征的dga生成域名的检测方法 |
CN106911717A (zh) * | 2017-04-13 | 2017-06-30 | 成都亚信网络安全产业技术研究院有限公司 | 一种域名检测方法及装置 |
CN107046586B (zh) * | 2017-04-14 | 2019-07-23 | 四川大学 | 一种基于类自然语言特征的算法生成域名检测方法 |
CN109120579B (zh) * | 2017-06-26 | 2021-05-07 | 中国电信股份有限公司 | 恶意域名的检测方法、装置及计算机可读存储介质 |
CN107612911B (zh) * | 2017-09-20 | 2020-05-01 | 杭州安恒信息技术股份有限公司 | 基于dns流量检测受感染主机和c&c服务器的方法 |
CN107645503B (zh) * | 2017-09-20 | 2020-01-24 | 杭州安恒信息技术股份有限公司 | 一种基于规则的恶意域名所属dga家族的检测方法 |
CN107786575B (zh) * | 2017-11-11 | 2020-07-10 | 北京信息科技大学 | 一种基于dns流量的自适应恶意域名检测方法 |
CN109788079B (zh) | 2017-11-15 | 2022-03-15 | 瀚思安信(北京)软件技术有限公司 | Dga域名实时检测方法和装置 |
CN108200034B (zh) * | 2017-12-27 | 2021-01-29 | 新华三信息安全技术有限公司 | 一种识别域名的方法及装置 |
CN108200054B (zh) * | 2017-12-29 | 2021-02-12 | 奇安信科技集团股份有限公司 | 一种基于dns解析的恶意域名检测方法及装置 |
CN108768954B (zh) * | 2018-05-04 | 2020-07-10 | 中国科学院信息工程研究所 | 一种dga恶意软件识别方法 |
CN109889616B (zh) * | 2018-05-21 | 2020-06-05 | 新华三信息安全技术有限公司 | 一种识别域名的方法及装置 |
CN108809989B (zh) * | 2018-06-14 | 2021-04-23 | 北京中油瑞飞信息技术有限责任公司 | 一种僵尸网络的检测方法及装置 |
WO2020014916A1 (zh) * | 2018-07-19 | 2020-01-23 | 华为技术有限公司 | 一种用户识别方法和相关设备 |
CN109246083B (zh) * | 2018-08-09 | 2021-08-03 | 奇安信科技集团股份有限公司 | 一种dga域名的检测方法及装置 |
CN109450842B (zh) * | 2018-09-06 | 2023-06-13 | 南京聚铭网络科技有限公司 | 一种基于神经网络的网络恶意行为识别方法 |
CN109450886A (zh) * | 2018-10-30 | 2019-03-08 | 杭州安恒信息技术股份有限公司 | 一种域名识别方法、系统及电子设备和存储介质 |
CN109688110A (zh) * | 2018-11-22 | 2019-04-26 | 顺丰科技有限公司 | Dga域名检测模型构建方法、装置、服务器及存储介质 |
CN111224919B (zh) * | 2018-11-23 | 2022-05-13 | 中移(杭州)信息技术有限公司 | 一种ddos识别方法、装置、电子设备及介质 |
CN111401391B (zh) * | 2019-01-02 | 2024-05-07 | 中国移动通信有限公司研究院 | 一种数据挖掘方法、装置及计算机可读存储介质 |
CN109714356A (zh) * | 2019-01-08 | 2019-05-03 | 北京奇艺世纪科技有限公司 | 一种异常域名的识别方法、装置及电子设备 |
CN110187955A (zh) * | 2019-05-27 | 2019-08-30 | 四川大学 | 一种动静态结合的Docker容器内容安全性检测方法和装置 |
CN110381089A (zh) * | 2019-08-23 | 2019-10-25 | 南京邮电大学 | 基于深度学习对恶意域名检测防护方法 |
US11729134B2 (en) * | 2019-09-30 | 2023-08-15 | Palo Alto Networks, Inc. | In-line detection of algorithmically generated domains |
CN110784483B (zh) * | 2019-11-04 | 2020-11-27 | 北京航空航天大学 | 一种基于dga异常域名的事件检测系统及方法 |
CN111556050B (zh) * | 2020-04-26 | 2022-06-07 | 山石网科通信技术股份有限公司 | 域名处理方法、装置、存储介质及处理器 |
CN113645173A (zh) * | 2020-04-27 | 2021-11-12 | 北京观成科技有限公司 | 一种恶意域名的识别方法、系统和设备 |
CN111581352B (zh) * | 2020-05-03 | 2022-05-27 | 南开大学 | 基于可信度的互联网恶意域名检测方法 |
CN111654504B (zh) * | 2020-06-10 | 2022-05-17 | 北京天融信网络安全技术有限公司 | 一种dga域名检测方法及装置 |
CN111935099A (zh) * | 2020-07-16 | 2020-11-13 | 兰州理工大学 | 一种基于深度降噪自编码网络的恶意域名检测方法 |
CN112468484B (zh) * | 2020-11-24 | 2022-09-20 | 山西三友和智慧信息技术股份有限公司 | 一种基于异常和信誉的物联网设备感染检测方法 |
CN113271292B (zh) * | 2021-04-07 | 2022-05-10 | 中国科学院信息工程研究所 | 一种基于词向量的恶意域名集群检测方法及装置 |
Citations (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN104735074A (zh) * | 2015-03-31 | 2015-06-24 | 江苏通付盾信息科技有限公司 | 一种恶意url检测方法及其实现系统 |
Family Cites Families (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US9106536B2 (en) * | 2013-04-15 | 2015-08-11 | International Business Machines Corporation | Identification and classification of web traffic inside encrypted network tunnels |
-
2015
- 2015-12-22 CN CN201510971299.XA patent/CN105577660B/zh active Active
Patent Citations (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN104735074A (zh) * | 2015-03-31 | 2015-06-24 | 江苏通付盾信息科技有限公司 | 一种恶意url检测方法及其实现系统 |
Non-Patent Citations (2)
Title |
---|
对邮件过滤技术发展现状的比较与分析;张 萍 韩立娜;《计算机与数字工程 2008年第44期》;20081231;全文 |
蔡冰 马旸 王林汝.一种恶意域名检测技术的研究与实现.《江苏通信 技术与实践 2015年8月刊》.2015, |
Also Published As
Publication number | Publication date |
---|---|
CN105577660A (zh) | 2016-05-11 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN105577660B (zh) | 基于随机森林的dga域名检测方法 | |
Alhogail et al. | Applying machine learning and natural language processing to detect phishing email | |
Le et al. | URLNet: Learning a URL representation with deep learning for malicious URL detection | |
Woodbridge et al. | Predicting domain generation algorithms with long short-term memory networks | |
CN107786575B (zh) | 一种基于dns流量的自适应恶意域名检测方法 | |
Peck et al. | CharBot: A simple and effective method for evading DGA classifiers | |
US10178107B2 (en) | Detection of malicious domains using recurring patterns in domain names | |
Vinayakumar et al. | Evaluating deep learning approaches to characterize and classify the DGAs at scale | |
US11762990B2 (en) | Unstructured text classification | |
US8112484B1 (en) | Apparatus and method for auxiliary classification for generating features for a spam filtering model | |
Rathod et al. | Content based spam detection in email using Bayesian classifier | |
CN106992969A (zh) | 基于域名字符串统计特征的dga生成域名的检测方法 | |
Thakur et al. | An intelligent algorithmically generated domain detection system | |
CN112073551B (zh) | 基于字符级滑动窗口和深度残差网络的dga域名检测系统 | |
Nowroozi et al. | An adversarial attack analysis on malicious advertisement URL detection framework | |
US12113828B2 (en) | System and method for detecting phishing-domains in a set of Domain Name System (DNS) records | |
CN110020430B (zh) | 一种恶意信息识别方法、装置、设备及存储介质 | |
Manasrah et al. | DGA-based botnets detection using DNS traffic mining | |
Phan et al. | User identification via neural network based language models | |
Aggarwal et al. | Exposing the Achilles’ heel of textual hate speech classifiers using indistinguishable adversarial examples | |
Selvi et al. | Toward optimal LSTM neural networks for detecting algorithmically generated domain names | |
CN116886400A (zh) | 一种恶意域名检测方法、系统及介质 | |
Chen et al. | Detection of DGA domains based on support vector machine | |
Aravena et al. | Dom2Vec-Detecting DGA Domains Through Word Embeddings and AI/ML-Driven Lexicographic Analysis | |
Wang | Botnet Detection via Machine Learning Techniques |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
C06 | Publication | ||
PB01 | Publication | ||
C10 | Entry into substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
GR01 | Patent grant | ||
GR01 | Patent grant | ||
CP01 | Change in the name or title of a patent holder |
Address after: 100031 Xicheng District West Chang'an Avenue, No. 86, Beijing Co-patentee after: INFORMATION & TELECOMMUNICATION BRANCH OF STATE GRID ZHEJIANG ELECTRONIC POWER Co. Patentee after: State Grid Corporation of China Co-patentee after: NARI Group Corp. Co-patentee after: NARI INFORMATION AND COMMUNICATION TECHNOLOGY Co. Address before: 100031 Xicheng District West Chang'an Avenue, No. 86, Beijing Co-patentee before: INFORMATION & TELECOMMUNICATION BRANCH OF STATE GRID ZHEJIANG ELECTRONIC POWER Co. Patentee before: State Grid Corporation of China Co-patentee before: NARI Group CORPORATION STATE GRID ELECTRIC POWER INSTITUTE Co-patentee before: NARI INFORMATION AND COMMUNICATION TECHNOLOGY Co. |
|
CP01 | Change in the name or title of a patent holder |