Graduate School and Research Center in Digital Sciences

A survey on malicious domains detection through DNS data analysis

Zhauniarovich, Yury; Khalil, Issa; Yu, Ting; Dacier, Marc

ACM Computing Surveys (CSUR), Vol.51, N°4, Article N°67, September 2018

Malicious domains are one of the major resources required for adversaries to run attacks over the Internet. Due to the important role of the Domain Name System (DNS), extensive research has been conducted to identify malicious domains based on their unique behavior relected in diferent phases of the life cycle of DNS queries and responses. Existing approaches difer signiicantly in terms of intuitions, data analysis methods as well as evaluation methodologies. This warrants a thorough systematization of the approaches and a careful review of the advantages and limitations of every group. In this paper,we perform such an analysis. In order to achieve this goal,we present the necessary background knowledge on DNS and malicious activities leveraging DNS. We describe a general framework of malicious domain detection techniques using DNS data. Applying this framework, we categorize existing approaches using several orthogonal viewpoints, namely (1) sources of DNS data and their enrichment, (2) data analysis methods, and (3) evaluation strategies and metrics. In each aspect, we discuss the important challenges that the research community should address in order to fully realize the power of DNS data analysis to ight against attacks leveraging malicious domains.

Document Doi Arxiv Bibtex

Title:A survey on malicious domains detection through DNS data analysis
Keywords:Malicious domains detection, Domain Name System
Type:Journal
Language:English
City:
Date:
Department:Digital Security
Eurecom ref:5508
Copyright: © ACM, 2018. This is the author's version of the work. It is posted here by permission of ACM for your personal use. Not for redistribution. The definitive version was published in ACM Computing Surveys (CSUR), Vol.51, N°4, Article N°67, September 2018 http://dx.doi.org/10.1145/3191329
Bibtex: @article{EURECOM+5508, doi = {http://dx.doi.org/10.1145/3191329}, year = {2018}, month = {09}, title = {{A} survey on malicious domains detection through {DNS} data analysis}, author = {{Z}hauniarovich, {Y}ury and {K}halil, {I}ssa and {Y}u, {T}ing and {D}acier, {M}arc}, journal = {{ACM} {C}omputing {S}urveys ({CSUR}), {V}ol.51, {N}°4, {A}rticle {N}°67, {S}eptember 2018}, url = {http://www.eurecom.fr/publication/5508} }
See also: