错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

C2 and Phishing Domains Detection Using DNS Analysis

  • Neelam Singh,
  • Gopika Vinod,
  • Akshat Kakkar,
  • Surya Pratap,
  • Gigi Joseph

摘要

As the Internet continues to evolve, cybercriminals employ increasingly sophisticated techniques to deceive users and orchestrate malicious activities. Phishing attacks and command-and-control (C2 or C&C) infrastructures pose significant threats to individuals, organizations and society as a whole. To address these challenges, we propose a comprehensive approach to detect both phishing domains and C2 domain names by analyzing Domain Name System (DNS) queries. For phishing domain detection, we adopt two distinct methodologies, “Edit distance with clustering algorithm” and “Long Short-Term Memory (LSTM) based model”, and for identifying random domain names associated with C2 activities, “Character level N-gram model” and “LSTM based model” are used. Additionally, we develop a comprehensive model that integrates the insights gained from the individual detection approaches to assess the potential maliciousness of any given domain name. The outcome of this research has the potential to enhance cybersecurity measures, defense against phishing attacks, and mitigate command and control activities.