计算机应用 ›› 2016, Vol. 36 ›› Issue (12): 3311-3316.DOI: 10.11772/j.issn.1001-9081.2016.12.3311

• 网络空间安全 • 上一篇    下一篇

基于权威域名服务器的停靠域名识别机制

刘梅, 张永斌, 冉崇善, 孙连山   

  1. 陕西科技大学 电气与信息工程学院, 西安 710021
  • 收稿日期:2016-06-30 修回日期:2016-09-05 出版日期:2016-12-10 发布日期:2016-12-08
  • 通讯作者: 冉崇善
  • 作者简介:刘梅(1989-),女,河北定州人,硕士研究生,主要研究方向:网络安全;张永斌(1976-),男,陕西西安人,讲师,博士,CCF会员,主要研究方向:网络安全;冉崇善(1956-),男,陕西渭南人,教授,硕士,CCF会员,主要研究方向:智能信息处理、计算机网络体系结构;孙连山(1977-),男,黑龙江集贤人,副教授,博士,主要研究方向:非功能需求、软件体系结构、软件安全工程。
  • 基金资助:
    国家自然科学基金资助项目(61202019)。

Mechanism of parked domain recognition based on authoritative domain name servers

LIU Mei, ZHANG Yongbin, RAN Chongshan, SUN Lianshan   

  1. College of Electrical and Information Engineering, Shaanxi University of Science and Technology, Xi'an Shaanxi 710021, China
  • Received:2016-06-30 Revised:2016-09-05 Online:2016-12-10 Published:2016-12-08
  • Supported by:
    This work is partially supported by the National Natural Science Foundation of China (61202019).

摘要: 由于互联网中充斥着大量的停靠域名,给用户上网体验、上网环境带来严重影响,为识别停靠域名,提出一种基于权威域名服务器(DNS)的停靠域名检测方法。该方法从常用于域名停靠服务的错拼域名入手,提取出可能用于停靠服务的权威DNS集合,并通过半监督聚类方法对该集合进行分析,识别出用于停靠服务的权威DNS。在检测停靠域名时,通过判断域名的权威DNS是否用于停靠服务,并且该域名解析的IP地址是否属于停靠服务Web服务器的IP地址集合,来对停靠域名进行识别。借助现有基于页面特征的检测方法对所提方法进行分析,实验结果表明所提方法的准确率达92.8%以上,并且避免了页面信息的爬取,能够实时地检测域名是否为停靠域名。

关键词: 停靠域名, 错拼域名, 域名停靠服务, 半监督聚类, 权威域名服务器

Abstract: The massive parked domains exist in the Internet, which seriously affect the Internet experience and Internet environment of online users when surfing. In order to recognize parked domains, a new method of parked domain recognition was proposed based on authoritative Domain Name Server (DNS). The set of authoritative DNS which could be used for domain parking service was extracted by the typosquatting domains commonly used in domain parking service. Then the set was clustered by semi-supervised clustering method to identify the authoritative DNS associated with domain parking service. When detecting a parked domain, the parked domain was recognized by the judgments that whether its authoritative DNS was applied in domain parking service and whether its mapped IP addresses was concluded in the set of IP addresses of parking Web servers. By using the existing detecting method based on webpages' features, the accuracy of the proposed method was analyzed. The experimental results show the proposed method has achieved the accuracy rate of 92.8%, and avoids crawling the webpage information, which has a good performance on parked domains detection in real-time.

Key words: parked domain, typosquatting domain, domain parking service, semi-supervised clustering, authoritative Domain Name Server (DNS)

中图分类号: