In-line detection of algorithmically generated domains
Detection of algorithmically generated domains is disclosed. A DNS query is received. Markov Chain analysis is performed on a domain included in the received query. A determination of whether the received query implicates an algorithmically generated domain is made based at least in part on a result of the Markov Chain analysis.
1. A system, comprising:
a processor configured to:
receive, at a first node, a DNS query in response to a client device making a DNS resolution request;
determine whether the received DNS query implicates an algorithmically generated domain (AGD) based at least in part by performing Markov Chain analysis on a domain included in the received DNS query; and
include, by the first node, in a response to the received DNS query, an indication that the DNS resolution request made by the client device is indicative of the client device engaging in AGD activity;
wherein the indication included in the response to the received DNS query is usable by a security appliance to at least partially remediate the client device; and
a memory coupled to the processor and configured to provide the processor with instructions.
2. The system of claim 1 , wherein determining whether the received DNS query implicates the algorithmically generated domain includes evaluating historical resolution information.
3. The system of claim 2 , wherein the historical resolution information comprises a count of resolutions.
4. The system of claim 2 , wherein the historical resolution information comprises an interval between a first resolution and a last resolution.
5. The system of claim 1 , wherein performing the Markov Chain analysis includes using a model trained at least in part using a set of known algorithmically generated domains.
6. The system of claim 1 , wherein performing the Markov Chain analysis includes using a model trained at least in part using a set of known benign domains.
7. The system of claim 1 , wherein determining whether the received DNS query implicates the AGD includes using a random forest trained using features extracted from a plurality of other AGDs.
8. The system of claim 7 , wherein at least one feature comprises a domain suffix.
9. The system of claim 7 , wherein at least one feature comprises a count of hyphens.
10. The system of claim 7 , wherein at least one feature comprises a domain length.
11. The system of claim 7 , wherein at least one feature comprises a distinct number of characters.
12. The system of claim 7 , wherein at least one feature comprises a ratio of digits to other characters.
13. The system of claim 7 , wherein at least one feature comprises whether a first character of a root domain is a digit.
14. A method, comprising:
receiving, at a first node, a DNS query in response to a client device making a DNS resolution request;
determining whether the received DNS query implicates an algorithmically generated domain (AGD) based at least in part by performing Markov Chain analysis on a domain included in the received DNS query; and
including, by the first node, in a response to the received DNS query, an indication that the DNS resolution request made by the client device is indicative of the client device engaging in AGD activity;
wherein the indication included in the response to the received DNS query is usable by a security appliance to at least partially remediate the client device.
15. A computer program product embodied in a tangible computer readable storage medium and comprising computer instructions for:
receiving, at a first node, a DNS query in response to a client device making a DNS resolution request;
determining whether the received DNS query implicates an algorithmically generated domain (AGD) based at least in part by performing Markov Chain analysis on a domain included in the received DNS query; and
including, by the first node, in a response to the received DNS query, an indication that the DNS resolution request made by the client device is indicative of the client device engaging in AGD activity;
wherein the indication included in the response to the received DNS query is usable by a security appliance to at least partially remediate the client device.
16. The system of claim 1 , wherein the security appliance is configured to alert an administrator that the client device is engaging in AGD activity.
17. The system of claim 1 , wherein the security appliance is configured to quarantine the client device.
18. The system of claim 1 , wherein the security appliance is configured to prevent communications between the client device and the AGD.
19. The method of claim 14 , wherein determining whether the received DNS query implicates the algorithmically generated domain includes evaluating historical resolution information.
20. The method of claim 19 , wherein the historical resolution information comprises a count of resolutions.
21. The method of claim 19 , wherein the historical resolution information comprises an interval between a first resolution and a last resolution.
22. The method of claim 14 , wherein performing the Markov Chain analysis includes using a model trained at least in part using a set of known algorithmically generated domains.
23. The method of claim 14 , wherein performing the Markov Chain analysis includes using a model trained at least in part using a set of known benign domains.
24. The method of claim 14 , wherein determining whether the received DNS query implicates the AGD includes using a random forest trained using features extracted from a plurality of other AGDs.
25. The method of claim 24 , wherein at least one feature comprises a domain suffix.
26. The method of claim 24 , wherein at least one feature comprises a count of hyphens.
27. The method of claim 24 , wherein at least one feature comprises a domain length.
28. The method of claim 24 , wherein at least one feature comprises a distinct number of characters.
29. The method of claim 24 , wherein at least one feature comprises a ratio of digits to other characters.
30. The method of claim 24 , wherein at least one feature comprises whether a first character of a root domain is a digit.