Using Anomaly Detection to find malicious domains
ID: 41a4377f-d14b-56cb-89ed-3759db0dc839
STIX ID: report--41a4377f-d14b-56cb-89ed-3759db0dc839
Feed Name: Fox-IT blog
This Fox-IT blog describes an unsupervised machine-learning method to detect domain generation algorithm (DGA) domains by modeling n-gram (trigram) probabilities from a large baseline of benign hostnames; domains with low normalized probability are flagged as DGA-like. The authors report training on ~8 million common names, testing against ~125k DGA domains, achieving high detection (≈94.7% true DGA) with a very low false-positive rate by using a strict cutoff, and argue the approach is lightweight, label-free, and applicable to DNS, HTTP, filenames, and other anomaly-detection use cases.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
