Lune

CCS2016顶会

PREDATOR: Proactive Recognition and Elimination of Domain Abuse at Time-Of-Registration

Shuang Hao, Alex Kantchelian, Brad Miller, Vern Paxson, Nick Feamster

2016年份
133被引次数
22顶会引用

摘要

Miscreants register thousands of new domains every day to launch Internet-scale attacks, such as spam, phishing, and drive-by downloads. Quickly and accurately determining a domain's reputation (association with malicious activity) provides a powerful tool for mitigating threats and protecting users. Yet, existing domain reputation systems work by observing domain use (e.g., lookup patterns, content hosted)-often too late to prevent miscreants from reaping benefits of the attacks that they launch. As a complement to these systems, we explore the extent to which features evident at domain registration indicate a domain's subsequent use for malicious activity. We develop PREDATOR, an approach that uses only time-of-registration features to establish domain reputation. We base its design on the intuition that miscreants need to obtain many domains to ensure profitability and attack agility, leading to abnormal registration behaviors (e.g., burst registrations, textually similar names). We evaluate PREDATOR using registration logs of second-level .com and .net domains over five months. PREDATOR achieves a 70% detection rate with a false positive rate of 0.35%, thus making it an effective-and early-first line of defense against the misuse of DNS domains. It predicts malicious domains when they are registered, which is typically days or weeks earlier than existing DNS blacklists. CCS Concepts •Security and privacy → Intrusion/anomaly detection and malware mitigation; •Networks → Network domains;

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

lune papers fulltext 45d2d7ee-9f9e-4074-82b3-ba91f07917e2

引用它的顶会 Paper22

问问它们各自怎么用它

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖