Related Experiment Video
Updated: Jan 21, 2026

Using the Threat Probability Task to Assess Anxiety and Fear During Uncertain and Certain Threat
Published on: September 12, 2014
AULD: Large Scale Suspicious DNS Activities Detection via Unsupervised Learning in Advanced Persistent Threats
Guanghua Yan1, Qiang Li1,2, Dong Guo2
1College of Computer Science and Technology, Jilin University, Changchun 130012, China.
This study introduces AULD, an unsupervised learning framework for detecting Advanced Persistent Threats (APTs) by identifying suspicious domains in DNS logs. AULD effectively detects all attack samples, enhancing network security against sophisticated cyber threats.
Area of Science:
- Cybersecurity
- Network Security
- Machine Learning
Background:
- Internet of Things (IoT) sensors are increasingly prevalent, yet possess low security levels, making them vulnerable targets for Advanced Persistent Threats (APTs).
- Traditional security measures struggle against complex, multi-stage APT attacks that exploit sensor vulnerabilities.
- APT attacks rely on DNS for communication, presenting an opportunity for detection through suspicious domain analysis, but challenges include large data volumes and limited attack samples for supervised learning.
Purpose of the Study:
- To propose a novel unsupervised learning framework, AULD (Advanced Persistent Threats Unsupervised Learning Detection), for identifying suspicious domains associated with APT attacks.
- To address the limitations of existing methods in handling large-scale DNS log data and small numbers of attack samples.
Main Methods:
- Extraction of ten key features from host, domain name, and time data within extensive DNS logs.
- Application of unsupervised learning to cluster suspicious domains from the processed DNS records.
- Classification of all domains within the identified cluster as malicious.
Main Results:
- The AULD framework successfully detected all known APT attack samples in the experimental dataset.
- The system demonstrated effectiveness in identifying suspicious domain names indicative of APT activities.
- Analysis of 1,584,225,274 DNS records from a university network validated the framework's performance.
Conclusions:
- AULD provides an effective unsupervised approach for detecting APTs by analyzing DNS logs.
- The framework overcomes challenges related to data scale and sample scarcity inherent in traditional supervised methods.
- AULD enhances network security by identifying malicious domains used in sophisticated cyberattacks.
Related Concept Videos
Stereotype Threat and Self-fulfilling Prophecies
Threats to Biodiversity
pH Scale
Avoidance Learning and Learned Helplessness
Avoidance learning occurs when an organism learns that a specific behavior can prevent an unpleasant outcome. For example, a student who receives a bad grade may start studying harder to avoid future poor grades. This behavior persists even when the negative outcome is no longer present. Avoidance learning is powerful because it maintains behavior in the absence of the...
Scaling
Extraction: Advanced Methods

