MANTIS: Detection of Zero-Day Malicious Domains Leveraging Low Reputed Hosting Infrastructure
Fatih Deniz, Mohamed Nabeel, Ting Yu, Issa Khalil

TL;DR
MANTIS is a system that detects and predicts malicious domains early by analyzing hosting infrastructure, achieving high accuracy and significantly increasing detection rates compared to existing methods.
Contribution
This work introduces MANTIS, a content-agnostic, infrastructure-based approach that accurately detects and predicts malicious domains before they appear in blocklists.
Findings
Achieves 99.7% precision and 86.9% recall in detecting malicious domains.
Detects on average 19,000 new malicious domains daily, over 5 times more than VirusTotal.
Predicts malicious domains days to weeks before they appear in popular blocklists.
Abstract
Internet miscreants increasingly utilize short-lived disposable domains to launch various attacks. Existing detection mechanisms are either too late to catch such malicious domains due to limited information and their short life spans or unable to catch them due to evasive techniques such as cloaking and captcha. In this work, we investigate the possibility of detecting malicious domains early in their life cycle using a content-agnostic approach. We observe that attackers often reuse or rotate hosting infrastructures to host multiple malicious domains due to increased utilization of automation and economies of scale. Thus, it gives defenders the opportunity to monitor such infrastructure to identify newly hosted malicious domains. However, such infrastructures are often shared hosting environments where benign domains are also hosted, which could result in a prohibitive number of false…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · Internet Traffic Analysis and Secure E-voting · Advanced Malware Detection Techniques
