Detection of Newly Registered Malicious Domains through Passive DNS

Registro completo de metadados
MetadadosDescriçãoIdioma
Autor(es): dc.contributorUniversidade Estadual Paulista (UNESP)-
Autor(es): dc.contributorBrazilian Network Informat Ctr NICbr-
Autor(es): dc.creatorSilveira, Marcos Rogerio-
Autor(es): dc.creatorSilva, Leandro Marcos da-
Autor(es): dc.creatorCansian, Adriano Mauro-
Autor(es): dc.creatorKobayashi, Hugo Koji-
Autor(es): dc.creatorChen, Y.-
Autor(es): dc.creatorLudwig, H.-
Autor(es): dc.creatorTu, Y.-
Autor(es): dc.creatorFayyad, U.-
Autor(es): dc.creatorZhu, X-
Autor(es): dc.creatorHu, X-
Autor(es): dc.creatorByna, S.-
Autor(es): dc.creatorLiu, X-
Autor(es): dc.creatorZhang, J.-
Autor(es): dc.creatorPan, S.-
Autor(es): dc.creatorPapalexakis, V-
Autor(es): dc.creatorWang, J.-
Autor(es): dc.creatorCuzzocrea, A.-
Autor(es): dc.creatorOrdonez, C.-
Data de aceite: dc.date.accessioned2025-08-21T20:33:43Z-
Data de disponibilização: dc.date.available2025-08-21T20:33:43Z-
Data de envio: dc.date.issued2022-11-29-
Data de envio: dc.date.issued2022-11-29-
Data de envio: dc.date.issued2020-12-31-
Fonte completa do material: dc.identifierhttp://dx.doi.org/10.1109/BigData52589.2021.9671348-
Fonte completa do material: dc.identifierhttp://hdl.handle.net/11449/237922-
Fonte: dc.identifier.urihttp://educapes.capes.gov.br/handle/11449/237922-
Descrição: dc.descriptionDue to the importance of DNS for the good functioning of the Internet, malicious users register domains for malicious purposes, such as the spreading of malware and the practice of phishing. In this work, an approach capable of detecting malicious domains just 72 hours after the first DNS query was developed. The data source used was the passive DNS collected from an authoritative TLD server with the enrichment of data later, which generated columns encompassing data related to geolocation, which resulted in 20 features. The model used Light-GBM as a machine learning algorithm, and oversampling and undersampling techniques for data balancing, such as Cluster Centroids and K-Means SMOTE, proving efficiency with an average AUC of 0.9763 and F1-score of 0.905, in addition to the TPR of 0.8656 in the validation of the model.-
Descrição: dc.descriptionFundação para o Desenvolvimento da UNESP (FUNDUNESP)-
Descrição: dc.descriptionSao Paulo State Univ UNESP, Sao Paulo, SP, Brazil-
Descrição: dc.descriptionBrazilian Network Informat Ctr NICbr, Brasilia, DF, Brazil-
Descrição: dc.descriptionSao Paulo State Univ UNESP, Sao Paulo, SP, Brazil-
Descrição: dc.descriptionFUNDUNESP: 2764/2018-
Formato: dc.format3360-3369-
Idioma: dc.languageen-
Publicador: dc.publisherIeee-
Relação: dc.relation2021 Ieee International Conference On Big Data (big Data)-
???dc.source???: dc.sourceWeb of Science-
Palavras-chave: dc.subjectDomain Name System-
Palavras-chave: dc.subjectPassive DNS-
Palavras-chave: dc.subjectMalicious Domains-
Palavras-chave: dc.subjectData Imbalanced-
Palavras-chave: dc.subjectMachine Learning-
Título: dc.titleDetection of Newly Registered Malicious Domains through Passive DNS-
Tipo de arquivo: dc.typeaula digital-
Aparece nas coleções:Repositório Institucional - Unesp

Não existem arquivos associados a este item.