Indexed by:
Abstract:
The Domain Name System (DNS) is an important core infrastructure of the Internet, domain names and IP addresses is a distributed database that maps to each other, however, due to the defects of its own protocol, there have been many malicious attacks against domain names, such as spoofing attacks, botnets, and domain name registrations, as a result, the security of domain names has become one of the problems that must be solved for the safe and reliable operation of the Internet. Based on the hidden Markov model (HMM), this paper analyzes the difference between the malicious domain name and the normal domain name in the various characteristics of DNS communication, and uses Spark's fast extraction to distinguish their attributes, the Baum-Welch algorithm and Viterbi algorithm in the Markov model can quickly classify unknown domain names accurately to achieve effective detection of malicious domain names. Finally, the HMM was compared with the commonly used random forest model through experiments, and the accuracy and recall rate were compared. The results show that the application of HMM improves the performance of the classifier to obtain more accurate detection results. © 2018 IEEE.
Keyword:
Reprint Author's Address:
Email:
Source :
Year: 2018
Page: 659-664
Language: English
Cited Count:
WoS CC Cited Count: 0
SCOPUS Cited Count: 3
ESI Highly Cited Papers on the List: 0 Unfold All
WanFang Cited Count:
Chinese Cited Count:
30 Days PV: 9
Affiliated Colleges: