A4 Vertaisarvioitu artikkeli konferenssijulkaisussa

Investigating the Agility Bias in DNS Graph Mining




TekijätJukka Ruohonen, Ville Leppänen

ToimittajaNo available

Konferenssin vakiintunut nimiIEEE International Conference on Computer and Information Technology

Julkaisuvuosi2017

Kokoomateoksen nimiProceedings of the 17th IEEE International Conference on Computer and Information Technology CIT 2017

Aloitussivu253

Lopetussivu260

Sivujen määrä8

ISBN978-1-5386-0959-0

eISBN978-1-5386-0958-3

DOIhttps://doi.org/10.1109/CIT.2017.55

Verkko-osoitehttp://ieeexplore.ieee.org/abstract/document/8031482/

Rinnakkaistallenteen osoitehttps://research.utu.fi/converis/portal/detail/Publication/26902271


Tiivistelmä

The concept of agile domain name system (DNS) refers to dynamic and rapidly changing mappings between domain names and their Internet protocol (IP) addresses. This empirical paper evaluates the bias from this kind of agility for DNS-based graph theoretical data mining applications. By building on two conventional metrics for observing malicious DNS agility, the agility bias is observed by comparing bipartite DNS graphs to different subgraphs from which vertices and edges are removed according to two criteria. According to an empirical experiment with two longitudinal DNS datasets, irrespective of the criterion, the agility bias is observed to be severe particularly regarding the effect of outlying domains hosted and delivered via content delivery networks and cloud computing services. With these observations, the paper contributes to the research domains of cyber security and DNS mining. In a larger context of applied graph mining, the paper further elaborates the practical concerns related to the learning of large and dynamic bipartite graphs.


Ladattava julkaisu

This is an electronic reprint of the original article.
This reprint may differ from the original in pagination and typographic detail. Please cite the original version.





Last updated on 2024-26-11 at 20:39