conference-paper

Detection of COVID-19-related Malicious Domain Names Based on Feature Fusion

Research footprint

At a glance

Citations
1
References
0
Comments
0
Paper overview

Abstract

Since its outbreak, coronavirus disease (COVID-19) has significantly impacted people's lives worldwide, with a large number of COVID-19-related cyberattacks. Cybercriminals have created many malicious websites and spam emails named after COVID-19-related terms to engage in malicious activities, taking advantage of the rise in online activity that people experience due to COVID-19. In this paper, we propose a feature fusion-based COVID-19-related malicious domain name detection method to detect COVID-19-related malicious domain names and block the malicious behaviors of attackers in time. Firstly, the WHOIS data of domain names in publicly available sources are obtained. Secondly, the global and local features are respectively extracted with Transformer network and one-dimension convolutional neural network (1DCNN) from COVID-19 domain name strings and WHOIS registration data. Finally, both the extracted global features and local features are fused and fed into the classifier to determine whether the domain name is malicious. The experimental results show that the proposed detection method has the accuracy rate of 99.24% and the precision rate of 99.42% on the self-built dataset. Both of these indicators are over 95% on the CIC-Bell-DNS 2021 dataset, which proves our method is efficient in detecting COVID-19-related malicious domain names and it has an excellent performance in detecting other malicious domain names.

Record transparency

Publication details

DOI
10.1109/cscwd57460.2023.10152588
OpenAlex
W4381734673
Document type
conference-paper
Language
EN
Last metadata update
Community

Comments

Log in to join the discussion.

  1. No comments yet. Start the discussion.