Research Article

An Imbalanced Malicious Domains Detection Method Based on Passive DNS Traffic Analysis

Table 1

An overview of domain features.

Feature groupNo.Feature NameMalicious domain profile

Static lexical features1Length of domain nameLonger
2Max length of labels in subdomainLonger
3Character entropyGreater
4Number of numerical charactersHigher
5Ratio of numerical charactersHigher
6Conversion frequency of numerical and alphabetic characterHigher
7Max length of continuous numerical charactersShorter
8Max length of continuous alphabetic charactersLonger
9Max length of continuous same alphabetic charactersShorter
10Ratio of vowelsLower
11Max length of continuous consonantsLonger
12Conversion frequency of vowel and consonantHigher

Dynamic DNS resolving features13Number of distinct A recordsHigher
14IP entropy of domain nameHigher
15Number of distinct NS recordsHigher
16Similarity of NS domain nameBigger