Detection of COVID-19-related Malicious Domain Names Based on Feature Fusion
At a glance
- Citations
- 1
- References
- 0
- Comments
- 0
Abstract
Since its outbreak, coronavirus disease (COVID-19) has significantly impacted people's lives worldwide, with a large number of COVID-19-related cyberattacks. Cybercriminals have created many malicious websites and spam emails named after COVID-19-related terms to engage in malicious activities, taking advantage of the rise in online activity that people experience due to COVID-19. In this paper, we propose a feature fusion-based COVID-19-related malicious domain name detection method to detect COVID-19-related malicious domain names and block the malicious behaviors of attackers in time. Firstly, the WHOIS data of domain names in publicly available sources are obtained. Secondly, the global and local features are respectively extracted with Transformer network and one-dimension convolutional neural network (1DCNN) from COVID-19 domain name strings and WHOIS registration data. Finally, both the extracted global features and local features are fused and fed into the classifier to determine whether the domain name is malicious. The experimental results show that the proposed detection method has the accuracy rate of 99.24% and the precision rate of 99.42% on the self-built dataset. Both of these indicators are over 95% on the CIC-Bell-DNS 2021 dataset, which proves our method is efficient in detecting COVID-19-related malicious domain names and it has an excellent performance in detecting other malicious domain names.
Publication details
- DOI
- 10.1109/cscwd57460.2023.10152588
- OpenAlex
- W4381734673
- Document type
- conference-paper
- Language
- EN
- Last metadata update
Comments
Log in to join the discussion.