ISSN 2996-8223
International Journal of Computer Science and Technology | Vol. 2, No. 11, November 2021 | pp. 81–88
Research Article
Title: An Automated Malicious Domain Detection Architecture Using Recurrent Neural Networks and Passive DNS Analysis
Names of Authors: Youssef Mansour¹, Hassan Farhat², and Fatima Al-Sayed³
Authors’ Affiliations:
¹Department of Computer Science, American University of Beirut, Beirut, Lebanon
²Faculty of Technology, Lebanese University, Sidon, Lebanon
³Department of Computer Engineering, Beirut Arab University, Beirut, Lebanon
Abstract: Cybercriminals regularly utilize algorithmic techniques like Domain Generation Algorithms (DGAs) to generate vast lists of temporary internet domains for command-and-control communication. Because these domains change rapidly, conventional reputation blacklists struggle to provide real-time protection, leaving enterprise networks vulnerable to ransomware and data extraction campaigns. This paper introduces an automated, high-precision malicious domain detection system that combines structural character analysis with passive DNS traffic modeling. The core architecture implements a long short-term memory (LSTM) recurrent neural network that checks string sequences to flag algorithmically generated domains before they receive active network requests. Simultaneously, a statistical profiling layer monitors passive DNS telemetry, assessing attributes like query frequency variations, geographic IP distributions, and resource record changes. Training and validation leverage a large dataset of 500,000 active domains, spanning both legitimate entries and real-world botnet traffic. Experimental metrics demonstrate an overall detection accuracy of 98.9% alongside a low false positive rate of 0.014%. The integrated detection engine processes incoming queries in less than 3.5 ms, making it highly effective for deployment within active corporate DNS gateways to block zero-day command-and-control communication channels.
Keywords: Network security, Domain generation algorithms, Long short-term memory, Passive DNS, Intrusion prevention, Cyber forensics
Manuscript Timeline: Received: August 18, 2021; Revised: September 22, 2021; Accepted: October 14, 2021; Published: November 1, 2021
Citation: Mansour, Y., Farhat, H., & Al-Sayed, F. (2021). An automated malicious domain detection architecture using recurrent neural networks and passive DNS analysis. International Journal of Computer Science and Technology, 2(11), 81–88. DOI: 10.46882/2021/IJCST/000023
Subscribe to read the full article: https://internationalscholarsjournals.org/subscribe-to-read