The invention discloses a DNS
domain name abnormal access
identification system based on behavior characteristics, which is oriented to
plaintext and encrypted DNS scenes, integrates multi-
source data such as terminal / process,
recursive analysis and passive DNS, and constructs a subject-
domain name-IP / CNAME multi-split graph and character level,
time sequence statistics, graph structure and protocol semantic four-dimensional portrait; through white / grey lists, CDN discrimination, TTL and IP quantity / similarity threshold values and DGA / Fast-Flux feature
rapid convergence candidates, an unsupervised / semi-supervised / supervised
hybrid model is used for scoring and evidence fusion to output an abnormal type and confidence; identifying abnormal relation evolution and gang by adopting a
time sequence diagram
attention network; automatic linkage and auditing trace leaving of graded alarm, DNS redirection / NXDOMAIN,
current limiting, terminal isolation and boundary blocking are supported; and online
incremental learning, feature / threshold recalibration and versioning management are carried out based on disposal feedback and information updating, so that high-accuracy and low-
delay identification and sustainable evolution protection of DGA, Fast-Flux,
domain name hijacking, DNS tunnel and abnormal equipment are realized.