An Improved Machine Learning Model for Detecting Malicious Domain Names
Open Access DepositedCybercriminals utilize malicious domains to breach computer networks, steal confidential information, and disrupt regular business operations. Nearly one-third of all cyberattacks worldwide use these malicious domains, making them a vital tool for hackers and costing billions of dollars. Akamai reported that over 20% of nearly 79 million new domains registered in the first half of year 2022 were malicious.A well-known example of how much damage a single malicious domain can inflict is the SolarWinds attack. In this case, hackers exploited a single malicious domain, specifically avsvmcloud[.]com, to infiltrate several nationally significant computer network systems. As a result of this attack, US businesses lost an average of 14% of their annual revenue. This incident shows that malicious domains not only pose a risk to data security but can also have a direct impact on an enterprise's bottom line. This praxis focuses on improving malicious domain detection capabilities by leveraging machine learning models and utilizing the CIC-Bell-DNS-2021 dataset. The dataset closely represents real-world traffic involving both benign and malicious domains. This study finds that the Random Forest classifier outperforms other ML algorithms in detecting malicious domains with 99.611% in accuracy for the imbalanced dataset and 97.713% in the balanced dataset.
- All rights reserved
Notice to Authors
If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.