域名观察者: 一个基于动态时间规整的轻量级的恶意域名检测方法

檀国林  张鹏  刘庆云 



People use the Internet to shop, access information and enjoy

entertainment by browsing web sites. At the same time, cyber-criminals

operate malicious domains to spread illegal information and acquire

money, which poses a great risk to the security of cyberspace. There-

fore, it is of great importance to detect malicious domains in the eld

of cyberspace security. Typically, there are broad research focusing on

detecting malicious domains either by blacklist or exploiting the features

via machine learning techniques. However, the former is infeasible due

to the limited crowd, and the later requires complex feature engineering.

Di erent from most of previous methods, in this paper, we propose a

novel lightweight solution named DomainObserver to detect malicious

domains. Our technique of DomainObserver is based on dynamic time

warping that is used to better align the time series. To the best of our

knowledge, it is a new trial to apply passive trac measurements and

time series data mining to malicious domain detection. Extensive exper-

iments on real datasets are performed to demonstrate the e ectiveness

of our proposed method.





首页
团队介绍
发展历史
组织结构
MESA大事记
新闻中心
通知
组内动态
科研成果
专利
论文
项目
获奖
软著
人才培养
MESA毕业生
MESA在读生
MESA员工
招贤纳士
走进MESA
学长分享
招聘通知
招生宣传
知识库
文章
地址:北京市朝阳区华严北里甲22号楼五层 | 邮编:100029
邮箱:nelist@iie.ac.cn
京ICP备15019404号-1