Detecting Malicious Domain Names Based on AGD

ZANG Xiaodong,GONG Jian,HU Xiaoyan
DOI: https://doi.org/10.11959/j.issn.1000-436x.2018116
2018-01-01
Abstract:A new malicious domain name detection algorithm was proposed.More specifically,the domain names in a cluster belonging to a DGA (domain generation algorithm) or its variants was identified firstly by using cluster correlation.Then,these AGD (algorithmically generated domain) names’ TTL,the distribution and attribution of their resolved IP addresses,their whois features and their historical information were extracted and further applied SVM algorithm to identify the malicious domain names.Experimental results demonstrate that it achieves an accuracy rate of 98.4% and the false positive of 0.9% without any client query records.
What problem does this paper attempt to address?