Extending black domain name list by using co-occurrence relation between DNS queries

  • Authors:
  • Kazumichi Sato;Keisuke Ishibashi;Tsuyoshi Toyono;Nobuhisa Miyake

  • Affiliations:
  • NTT Information Sharing Platform Laboratories, NTT Corporation;NTT Information Sharing Platform Laboratories, NTT Corporation;Internet Multifeed co.;NTT Information Sharing Platform Laboratories, NTT Corporation

  • Venue:
  • LEET'10 Proceedings of the 3rd USENIX conference on Large-scale exploits and emergent threats: botnets, spyware, worms, and more
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

The Botnet threats, such as server attacks or sending of spam email, have been increasing. A method of using a blacklist of domain names has been proposed to find infected hosts. However, not all infected hosts may be found by this method because a blacklist does not cover all black domain names. In this paper, we present a method for finding unknown black domain names and extend the blacklist by using DNS traffic data and the original blacklist of known black domain names. We use co-occurrence relation of two different domain names to find unknown black domain names and extend a blacklist. If a domain name co-occurs with a known black name frequently, we assume that the domain name is also black. We evaluate the proposed method by cross validation, about 91 % of domain names that are in the validation list can be found as top 1 %.