logo

Using Anomaly Detection to find malicious domains

ID: 41a4377f-d14b-56cb-89ed-3759db0dc839

STIX ID: report--41a4377f-d14b-56cb-89ed-3759db0dc839

Feed Name: Fox-IT blog

Threat Score
10/100

Date Published: 2019-06-11

Date Updated: 2026-04-27

Author: Fox It

...
...

This Fox-IT blog describes an unsupervised machine-learning method to detect domain generation algorithm (DGA) domains by modeling n-gram (trigram) probabilities from a large baseline of benign hostnames; domains with low normalized probability are flagged as DGA-like. The authors report training on ~8 million common names, testing against ~125k DGA domains, achieving high detection (≈94.7% true DGA) with a very low false-positive rate by using a strict cutoff, and argue the approach is lightweight, label-free, and applicable to DNS, HTTP, filenames, and other anomaly-detection use cases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.