216.73.216.233

Profiling and Detecting Malicious DNS Traffic

· Published 21/08/2024 13:07 · Modified 21/08/2024 13:29

Export JSON

Essential information

Published
21/08/2024 13:07
Modified
21/08/2024 13:29
Tags
2024-08-21 dns
Related entities
5 observables, 16 techniques (mitre)

Description

To improve our detection of suspicious network activity, we developed a deep learning method to profile and detect malicious traffic patterns. Based on these profiles, we implemented multiple detection modules designed to identify suspicious domains from different perspectives. We explored how these traffic patterns correlate with specific types of cyberattacks through various case studies. Our detector captured 170 emerging suspicious domains in May 2024, blocking approximately 374,000 malicious requests every day.

External references