Matches in SemOpenAlex for { <https://semopenalex.org/work/W1498756827> ?p ?o ?g. }
Showing items 1 to 85 of
85
with 100 items per page.
- W1498756827 abstract "In this paper, we propose Segugio, a novel defense system that allows for efficiently tracking the occurrence of new malware-control domain names in very large ISP networks. Segugio passively monitors the DNS traffic to build a machine-domain bipartite graph representing who is querying what. After labelling nodes in this query behavior graph that are known to be either benign or malware-related, we propose a novel approach to accurately detect previously unknown malware-control domains. We implemented a proof-of-concept version of Segugio and deployed it in large ISP networks that serve millions of users. Our experimental results show that Segugio can track the occurrence of new malware-control domains with up to 94% true positives (TPs) at less than 0.1% false positives (FPs). In addition, we provide the following results: (1) we show that Segugio can also detect control domains related to new, previously unseen malware families, with 85% TPs at 0.1% FPs, (2) Segugio's detection models learned on traffic from a given ISP network can be deployed into a different ISP network and still achieve very high detection accuracy, (3) new malware-control domains can be detected days or even weeks before they appear in a large commercial domain name blacklist, and (4) we show that Segugio clearly outperforms Notos, a previously proposed domain name reputation system." @default.
- W1498756827 created "2016-06-24" @default.
- W1498756827 creator A5016852181 @default.
- W1498756827 creator A5067105657 @default.
- W1498756827 creator A5071832270 @default.
- W1498756827 date "2015-06-01" @default.
- W1498756827 modified "2023-09-26" @default.
- W1498756827 title "Segugio: Efficient Behavior-Based Tracking of Malware-Control Domains in Large ISP Networks" @default.
- W1498756827 cites W1507388815 @default.
- W1498756827 cites W1983776999 @default.
- W1498756827 cites W2044285442 @default.
- W1498756827 cites W2101492723 @default.
- W1498756827 cites W2114590627 @default.
- W1498756827 cites W2122226347 @default.
- W1498756827 cites W2170214103 @default.
- W1498756827 cites W2482374127 @default.
- W1498756827 cites W2911964244 @default.
- W1498756827 doi "https://doi.org/10.1109/dsn.2015.35" @default.
- W1498756827 hasPublicationYear "2015" @default.
- W1498756827 type Work @default.
- W1498756827 sameAs 1498756827 @default.
- W1498756827 citedByCount "73" @default.
- W1498756827 countsByYear W14987568272016 @default.
- W1498756827 countsByYear W14987568272017 @default.
- W1498756827 countsByYear W14987568272018 @default.
- W1498756827 countsByYear W14987568272019 @default.
- W1498756827 countsByYear W14987568272020 @default.
- W1498756827 countsByYear W14987568272021 @default.
- W1498756827 countsByYear W14987568272022 @default.
- W1498756827 countsByYear W14987568272023 @default.
- W1498756827 crossrefType "proceedings-article" @default.
- W1498756827 hasAuthorship W1498756827A5016852181 @default.
- W1498756827 hasAuthorship W1498756827A5067105657 @default.
- W1498756827 hasAuthorship W1498756827A5071832270 @default.
- W1498756827 hasConcept C124101348 @default.
- W1498756827 hasConcept C132525143 @default.
- W1498756827 hasConcept C134306372 @default.
- W1498756827 hasConcept C154945302 @default.
- W1498756827 hasConcept C182590292 @default.
- W1498756827 hasConcept C197657726 @default.
- W1498756827 hasConcept C2781345505 @default.
- W1498756827 hasConcept C31258907 @default.
- W1498756827 hasConcept C33923547 @default.
- W1498756827 hasConcept C36503486 @default.
- W1498756827 hasConcept C38652104 @default.
- W1498756827 hasConcept C41008148 @default.
- W1498756827 hasConcept C506615639 @default.
- W1498756827 hasConcept C541664917 @default.
- W1498756827 hasConcept C64869954 @default.
- W1498756827 hasConcept C76155785 @default.
- W1498756827 hasConcept C80444323 @default.
- W1498756827 hasConceptScore W1498756827C124101348 @default.
- W1498756827 hasConceptScore W1498756827C132525143 @default.
- W1498756827 hasConceptScore W1498756827C134306372 @default.
- W1498756827 hasConceptScore W1498756827C154945302 @default.
- W1498756827 hasConceptScore W1498756827C182590292 @default.
- W1498756827 hasConceptScore W1498756827C197657726 @default.
- W1498756827 hasConceptScore W1498756827C2781345505 @default.
- W1498756827 hasConceptScore W1498756827C31258907 @default.
- W1498756827 hasConceptScore W1498756827C33923547 @default.
- W1498756827 hasConceptScore W1498756827C36503486 @default.
- W1498756827 hasConceptScore W1498756827C38652104 @default.
- W1498756827 hasConceptScore W1498756827C41008148 @default.
- W1498756827 hasConceptScore W1498756827C506615639 @default.
- W1498756827 hasConceptScore W1498756827C541664917 @default.
- W1498756827 hasConceptScore W1498756827C64869954 @default.
- W1498756827 hasConceptScore W1498756827C76155785 @default.
- W1498756827 hasConceptScore W1498756827C80444323 @default.
- W1498756827 hasLocation W14987568271 @default.
- W1498756827 hasOpenAccess W1498756827 @default.
- W1498756827 hasPrimaryLocation W14987568271 @default.
- W1498756827 hasRelatedWork W1561983441 @default.
- W1498756827 hasRelatedWork W1827256152 @default.
- W1498756827 hasRelatedWork W2253166131 @default.
- W1498756827 hasRelatedWork W2509891819 @default.
- W1498756827 hasRelatedWork W2514488323 @default.
- W1498756827 hasRelatedWork W2759618680 @default.
- W1498756827 hasRelatedWork W2951313964 @default.
- W1498756827 hasRelatedWork W3142179327 @default.
- W1498756827 hasRelatedWork W4281930654 @default.
- W1498756827 hasRelatedWork W4312347107 @default.
- W1498756827 isParatext "false" @default.
- W1498756827 isRetracted "false" @default.
- W1498756827 magId "1498756827" @default.
- W1498756827 workType "article" @default.