Domainobserver: A Lightweight Solution For Detecting Malicious Domains Based On Dynamic Time Warping

Guolin Tan,Peng Zhang,Qingyun Liu,Xinran Liu,Chunge Zhu
DOI: https://doi.org/10.1007/978-3-319-93698-7_16
2018-01-01
Abstract:People use the Internet to shop, access information and enjoy entertainment by browsing web sites. At the same time, cyber-criminals operate malicious domains to spread illegal content, which poses a great risk to the security of cyberspace. Therefore, it is of great importance to detect malicious domains in the field of cyberspace security. Typically, there are broad research focusing on detecting malicious domains either by blacklist or learning the features. However, the former is infeasible due to its unpredictability of unknown malicious domains, and the later requires complex feature engineering. Different from most of previous methods, in this paper, we propose a novel lightweight solution named DomainObserver to detect malicious domains. Our technique of DomainObserver is based on dynamic time warping that is used to better align the time series. To the best of our knowledge, it is a new trial to apply passive traffic measurements and time series data mining to malicious domain detection. Extensive experiments on real datasets are performed to demonstrate the effectiveness of our proposed method.
What problem does this paper attempt to address?