A4 Vertaisarvioitu artikkeli konferenssijulkaisussa
Investigating the Agility Bias in DNS Graph Mining
Tekijät: Jukka Ruohonen, Ville Leppänen
Toimittaja: No available
Konferenssin vakiintunut nimi: IEEE International Conference on Computer and Information Technology
Julkaisuvuosi: 2017
Kokoomateoksen nimi: Proceedings of the 17th IEEE International Conference on Computer and Information Technology CIT 2017
Aloitussivu: 253
Lopetussivu: 260
Sivujen määrä: 8
ISBN: 978-1-5386-0959-0
eISBN: 978-1-5386-0958-3
DOI: https://doi.org/10.1109/CIT.2017.55
Verkko-osoite: http://ieeexplore.ieee.org/abstract/document/8031482/
Rinnakkaistallenteen osoite: https://research.utu.fi/converis/portal/detail/Publication/26902271
The concept of agile domain name system (DNS) refers to dynamic and rapidly changing mappings between domain names and their Internet protocol (IP) addresses. This empirical paper evaluates the bias from this kind of agility for DNS-based graph theoretical data mining applications. By building on two conventional metrics for observing malicious DNS agility, the agility bias is observed by comparing bipartite DNS graphs to different subgraphs from which vertices and edges are removed according to two criteria. According to an empirical experiment with two longitudinal DNS datasets, irrespective of the criterion, the agility bias is observed to be severe particularly regarding the effect of outlying domains hosted and delivered via content delivery networks and cloud computing services. With these observations, the paper contributes to the research domains of cyber security and DNS mining. In a larger context of applied graph mining, the paper further elaborates the practical concerns related to the learning of large and dynamic bipartite graphs.
Ladattava julkaisu This is an electronic reprint of the original article. |