Finding disposable domain names: A linguistics-based stacking approach

An increasing number of Internet services tend to collect one-time information from clients via DNS queries. Notably, the uncertainty of such transient information makes these domain names be queried only once in their lifetime. This type of domain is called disposable domain. Although they do not i...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Veröffentlicht in:Computer networks (Amsterdam, Netherlands : 1999) Netherlands : 1999), 2021-01, Vol.184, p.107642, Article 107642
Hauptverfasser: Zeng, Yuwei, Yun, Xiaochun, Chen, Xunxun, Li, Boquan, Tsang, Haiwei, Wang, Yipeng, Zang, Tianning, Zhang, Yongzheng
Format: Artikel
Sprache:eng
Schlagworte:
Online-Zugang:Volltext
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:An increasing number of Internet services tend to collect one-time information from clients via DNS queries. Notably, the uncertainty of such transient information makes these domain names be queried only once in their lifetime. This type of domain is called disposable domain. Although they do not involve any malicious activities, the efficiency of DNS infrastructures is still affected by their ever-increasing number. Existing approaches for detecting disposable domains have serious disadvantages, such as poor timeliness and high false positive rate. In this paper, we conduct an extensive measurement study of the ISP-level DNS traffic and find that the readability of domain name is suitable for identifying disposable domains. Therefore, we propose Vogers, a linguistics-based stacking model, to detect disposable domains from raw DNS traffic. Compared with the prior arts, Vogers decreases the false positive rate by more than 17%, while maintaining the true positive rate above 98.9%. In addition, Vogers generalizes quite well to unknown environments, whereby we are able to report new disposable domains. Our further application of Vogers in the real-world DNS traffic shows that filtering disposable domains can improve the efficiency of DNS infrastructures.
ISSN:1389-1286
1872-7069
DOI:10.1016/j.comnet.2020.107642