Loading [MathJax]/extensions/MathMenu.js
Ensemble-based Feature Selection and Classification Model for DNS Typo-squatting Detection | IEEE Conference Publication | IEEE Xplore

Ensemble-based Feature Selection and Classification Model for DNS Typo-squatting Detection


Abstract:

Domain Name System (DNS) plays in important role in the current IP-based Internet architecture. This is because it performs the domain name to IP resolution. However, the...Show More

Abstract:

Domain Name System (DNS) plays in important role in the current IP-based Internet architecture. This is because it performs the domain name to IP resolution. However, the DNS protocol has several security vulnerabilities due to the lack of data integrity and origin authentication within it. This paper focuses on one particular security vulnerability, namely typo-squatting. Typo-squatting refers to the registration of a domain name that is extremely similar to that of an existing popular brand with the goal of redirecting users to malicious/suspicious websites. The danger of typo-squatting is that it can lead to information threat, corporate secret leakage, and can facilitate fraud. This paper builds on our previous work in [1], which only proposed majority-voting based classifier, by proposing an ensemble-based feature selection and bagging classification model to detect D NS typo-squatting attack. Experimental results show that the proposed framework achieves high accuracy and precision in identifying the malicious/suspicious typo-squatting domains (a loss of at most 1.5% in accuracy and 5% in precision when compared to the model that used the complete feature set) while having a lower computational complexity due to the smaller feature set (a reduction of more than 50 % in feature set size).
Date of Conference: 30 August 2020 - 02 September 2020
Date Added to IEEE Xplore: 19 November 2020
ISBN Information:

ISSN Information:

Conference Location: London, ON, Canada
No metrics found for this document.

I. Introduction

The Domain Name System (DNS) protocol is an important pillar in the Internet's current and future architecture [2]–[5]. This is because it is the standard mechanism for name to IP address resolution [2]. Moreover, it helps users to determine the location of servers and mailing hosts, resulting in a direct impact on the data exchange process [2], [3].

Usage
Select a Year
2025

View as

Total usage sinceNov 2020:350
0123456JanFebMarAprMayJunJulAugSepOctNovDec512000000000
Year Total:8
Data is updated monthly. Usage includes PDF downloads and HTML views.
Contact IEEE to Subscribe

References

References is not available for this document.