Research Article

An Imbalanced Malicious Domains Detection Method Based on Passive DNS Traffic Analysis

Table 2

The macroaveraged P, R, and F1 score comparison of four schemes.

HAC_EasyEnsembleEasyEnsemble
Complete LinkGroup AverageWard’s Methodnon-clustering
PrecisionRecallF1PrecisionRecallF1PrecisionRecallF1PrecisionRecallF1

Benign0.97120.95000.96050.97740.95910.96820.98370.96220.97280.95340.93750.9454
Malicious0.95520.95330.95420.94910.95670.95290.96510.96670.96590.91810.93000.9240
Macro-ave0.96320.95170.95740.96330.95790.96050.97440.96450.96940.93580.93380.9347