Malicious Domain Name Detection System
By Auke Zwaan
Name Detection System By Auke Zwaan DNS DNS DNS Give me google. - - PowerPoint PPT Presentation
Malicious Domain Name Detection System By Auke Zwaan DNS DNS DNS Give me google. gle.nl nl DNS Give me google. gle.nl nl Okay. 64.233. 4.233.166.9 66.94 Research Question Is it possible to detect ma malic iciou ious do domain
By Auke Zwaan
Give me google. gle.nl nl
Give me google. gle.nl nl
4.233.166.9 66.94
Nice, but what is a βma malicious icious domain main name meβ?
424 domains
15 domains
14 domains
6 domains Total 459 domains
Sour urce ce Target rget Time mestam stamp
192.168.0.105 google.nl 1452091187 192.168.0.106 uva.nl 1452091187 192.168.0.232 nu.nl 1452091187 145.100.104.208
1452091187 192.168.0.108 bdcrqgonzmwuehky.nl 1452091187 145.100.104.208 hzmksreiuojy.nl 1452091187 145.100.104.208 xjpakmdcfuqe.nl 1452091187
192.168.0.105 google.nl 192.168.0.106 uva.nl 192.168.0.232 nu.nl 145.100.104.208
192.168.0.108 bdcrqgonzmwuehky.nl 145.100.104.208 hzmksreiuojy.nl 145.100.104.208 xjpakmdcfuqe.nl
192.168.0.105 google.nl 192.168.0.106 uva.nl 192.168.0.232 nu.nl 145.100.104.208
192.168.0.108 bdcrqgonzmwuehky.nl 145.100.104.208 hzmksreiuojy.nl 145.100.104.208 xjpakmdcfuqe.nl
145.100.104.208
hzmksreiuojy.nl xjpakmdcfuqe.nl aanrechtblad-kopen.nl 192.168.0.108 bdcrqgonzmwuehky.nl replicarolex.nl google.nl
145.100.104.208
Unknown hzmksreiuojy.nl Yes xjpakmdcfuqe.nl Yes aanrechtblad-kopen.nl Unknown 192.168.0.108 bdcrqgonzmwuehky.nl Yes replicarolex.nl Unknown google.nl Unknown
145.100.104.208 2 2 192.168.0.108 1 2 192.168.0.106 1 6 192.168.0.105 1 5
ππππππππ£π‘πππ‘π‘ πππ’ππ = ππ£ππππ ππ ππ£ππ πππ‘ π’π πππππ ππππ πππππππ ππ£ππππ ππ ππ£ππ πππ‘ π’π πππππππ πππππππ
145.100.104.208 2 2 1.0 1.0 192.168.0.108 1 2 0.5 192.168.0.106 1 6 0.167 67 192.168.0.105 1 4 0.25 25 192.168.0.232 4 300 0.013
A ma malicious icious res esolv lver er is a resolver for which the maliciousness ratio β₯ 0.25
145.100.104.208 2 2 1.0 1.0 192.168.0.108 1 2 0.5 192.168.0.106 1 6 0.167 67 192.168.0.105 1 4 0.25 25 192.168.0.232 4 300 0.013
icious ious res esolv lver ers
The 100 most popular .nl domain names are not ma malicious icious
469 queries to malicious domains
673 malicious resolvers (maliciousness ratio β₯ 0.25)
392 potentially malicious domains (minus top 100)
If a website has at t lea east st one hit in VirusTotal in the past, it is considered malicious
www.ikhouvanirakezen.nl
Detected by VirusTotal thus tr true positiv itive
No hits on VirusTotal
Classification βYesβ
Classification βNoβ
Classification βPossiblyβ
Classifcation βUnknownβ
Ma Mali liciou cious Numb mber er of doma mains ins Yes 125 No 153 Possibly 111 Unknown 3 Total tal 392 92
Min Max Mean Std # # Pot
ntia ially maliciou cious domai ains ns 114 400 400 349.875 75 68.295 # # From test t set et found und 5 2.594 94 1. 1.316
spatial co-occurrence of DNS queries
(i.e. crawling), and apply NLP
commonly found domains
for finding malicious registrars
resolvers