A Topology Based Flow Model for Computing Domain Reputation - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2015

A Topology Based Flow Model for Computing Domain Reputation

Igor Mishsky
  • Fonction : Auteur
  • PersonId : 1029886
Nurit Gal-Oz
  • Fonction : Auteur
  • PersonId : 990584
Ehud Gudes
  • Fonction : Auteur
  • PersonId : 978093

Résumé

The Domain Name System (DNS) is an essential component of the internet infrastructure that translates domain names into IP addresses. Recent incidents verify the enormous damage of malicious activities utilizing DNS such as bots that use DNS to locate their command&control servers. Detecting malicious domains using the DNS network is therefore a key challenge.We project the famous expression Tell me who your friends are and I will tell you who you are, motivating many social trust models, on the internet domains world. A domain that is related to malicious domains is more likely to be malicious as well.In this paper, our goal is to assign reputation values to domains and IPs indicating the extent to which we consider them malicious. We start with a list of domains known to be malicious or benign and assign them reputation scores accordingly. We then construct a DNS based graph in which nodes represent domains and IPs.Our new approach for computing domain reputation applies a flow algorithm on the DNS graph to obtain the reputation of domains and identify potentially malicious ones. The experimental evaluation of the flow algorithm demonstrates its success in predicting malicious domains.
Fichier principal
Vignette du fichier
340025_1_En_20_Chapter.pdf (593.49 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01745814 , version 1 (28-03-2018)

Licence

Paternité

Identifiants

Citer

Igor Mishsky, Nurit Gal-Oz, Ehud Gudes. A Topology Based Flow Model for Computing Domain Reputation. 29th IFIP Annual Conference on Data and Applications Security and Privacy (DBSEC), Jul 2015, Fairfax, VA, United States. pp.277-292, ⟨10.1007/978-3-319-20810-7_20⟩. ⟨hal-01745814⟩
166 Consultations
340 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More