Fast-Flux Dataset: Enhancing Cybersecurity Analysis and Defense
Abstract
1. Introduction and Background
- (i)
- Could a detector be trained and evaluated using a fixed and publicly available collection of fast-flux and harmless domains, in such a way that the two reported accuracies mean the same thing?
- (ii)
- What characteristics of a domain include the fast-flux signal when the spread, the registration history, the certificate history, and the file relationships are all available?
- (iii)
- To what extent can a detector be applied in difficult cases, that is, in legitimate domains which are also served from several addresses in several countries?
- (iv)
- What is the state of the supporting infrastructure for the reuse of addresses across campaigns, the concentration of registrars, and the lengths of time for which certificates are valid?
1.1. Threat Model
1.2. Background and Related Work
1.3. Positioning Against Existing Datasets
1.4. Value of the Data
2. Data Description
2.1. Repository Structure
2.2. Record Content
2.3. Feature Dataset
3. Methods
4. User Notes
4.1. Intended Use
4.2. Reference Evaluation Protocol
- Splitting: Five-fold stratified cross-validation over the 91,530 records.
- Leakage control: Group folds by registered parent domain. Subdomains of one parent share hosting and registration properties, so splitting them across folds inflates every metric.
- Excluded columns: Drop Domain. Train on the 19 numeric and categorical features and predict Label.
- Metrics: Report per-class true positive rate, false positive rate, precision, recall, and F1, and report the false positive rate at a fixed true positive rate of 0.95. Accuracy may be quoted, but only next to the per-class rates: the classes are unbalanced at roughly three to one, so a classifier that labels everything fast flux already scores 73.9%.
- Hard negatives: Repeat the evaluation on the Task 2 subset and report both numbers.
4.3. Feature Distributions
4.4. Structure of the Feature Space
4.5. Baseline Results
4.6. Feature Importance
4.7. Reading the Baseline Against Published Results
4.8. Limitations
Supplementary Materials
Author Contributions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Acknowledgments
Conflicts of Interest
Abbreviations
| ASN | Autonomous System Number |
| C2 | Command and Control |
| CDN | Content Delivery Network |
| DNS | Domain Name System |
| FFN | Fast-Flux Network |
| PCA | Principal Component Analysis |
| PDNS | Protective Domain Name System |
| SSL | Secure Sockets Layer |
| TLD | Top-Level Domain |
| TTL | Time To Live |
References
- National Security Agency; Cybersecurity and Infrastructure Security Agency; Federal Bureau of Investigation; Australian Signals Directorate’s Australian Cyber Security Centre; Canadian Centre for Cyber Security; New Zealand National Cyber Security Centre. Fast Flux: A National Security Threat. Joint Cybersecurity Advisory AA25-093A. 2025. Available online: https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-093a (accessed on 1 September 2026).
- MITRE. Dynamic Resolution: Fast Flux DNS (T1568.001) and Detection Strategy DET0485. MITRE ATT&CK Enterprise Matrix, 2025. Available online: https://attack.mitre.org/detectionstrategies/DET0485/ (accessed on 1 September 2026).
- Zang, X.D.; Gong, J.; Mo, S.H.; Jakalan, A.; Ding, D.L. Identifying Fast-Flux Botnet with AGD Names at the Upper DNS Hierarchy. IEEE Access 2018, 6, 69713–69727. [Google Scholar] [CrossRef] [Scilit]
- Lombardo, P.; Saeli, S.; Bisio, F.; Bernardi, D.; Massa, D. Fast Flux Service Network Detection via Data Mining on Passive DNS Traffic. In Proceedings of the Information Security (ISC 2018), Guildford, UK, 9–12 September 2018; Volume 11060, pp. 463–480. [Google Scholar] [CrossRef] [Scilit]
- Al-Duwairi, B.; Jarrah, M.; Shatnawi, A.S. PASSVM: A Highly Accurate Fast Flux Detection System. Comput. Secur. 2021, 110, 102431. [Google Scholar] [CrossRef] [Scilit]
- Zhu, Z.; Lu, G.; Chen, Y. Botnet research survey. In Proceedings of the 2008 32nd Annual IEEE International Computer Software and Applications Conference, Turku, Finland, 28 July–1 August 2008; pp. 967–972. [Google Scholar]
- Ayo, F.E.; Awotunde, J.B.; Folorunso, S.O.; Adigun, M.O.; Ajagbe, S.A. A genomic rule-based KNN model for fast flux botnet detection. Egypt. Inform. J. 2023, 24, 313–325. [Google Scholar] [CrossRef] [Scilit]
- Zeidanloo, H.R.; Shooshtari, M.J.Z. A taxonomy of botnet detection techniques. In Proceedings of the 2010 3rd International Conference on Computer Science and Information Technology, Chengdu, China, 9–11 July 2010; pp. 158–162. [Google Scholar]
- Provos, N. A virtual honeypot framework. In Proceedings of the USENIX Security Symposium, San Diego, CA, USA, 9–13 August 2004; pp. 1–14. [Google Scholar]
- Vrable, M.; Ma, J.; Chen, J.; Moore, D.; Vandekieft, E.; Snoeren, A.C.; Voelker, G.M.; Savage, S. Scalability, fidelity, and containment in the potemkin virtual honeyfarm. SIGOPS Oper. Syst. Rev. 2005, 39, 148–162. [Google Scholar] [CrossRef] [Scilit]
- Bajtos, T.; Sokol, P. Virtual honeypots and detection of telnet botnets. In Proceedings of the Central European Cybersecurity Conference, Ljubljana, Slovenia, 15–16 November 2018; pp. 1–6. [Google Scholar]
- Gu, G.; Porras, P.A. Bothunter: Detecting malware infection through IDS-driven dialog correlation. In Proceedings of the USENIX Security Symposium, Boston, MA, USA, 6–10 August 2007; pp. 1–16. [Google Scholar]
- Chen, T.; Zhou, G.; Liu, Z.; Jing, T. A novel ensemble anomaly-based approach for command and control channel detection. In Proceedings of the 2020 4th International Conference on Cryptography, Security and Privacy, Nanjing, China, 10–12 January 2020; pp. 74–78. [Google Scholar]
- Martinez-Bea, S.; Castillo-Perez, S.; Garcia-Alfaro, J. Real-time malicious fast-flux detection using DNS and bot-related features. In Proceedings of the 2013 Eleventh Annual Conference on Privacy, Security and Trust, Tarragona, Spain, 10–12 July 2013; pp. 369–372. [Google Scholar]
- Alieyan, K.; Almomani, A.; Anbar, M.; Alauthman, M.; Abdullah, R.; Gupta, B.B. DNS rule-based schema for botnet detection. Enterp. Inf. Syst. 2021, 15, 545–564. [Google Scholar] [CrossRef] [Scilit]
- Ibrahim, W.N.H.; Anuar, S.; Selamat, A.; Krejcar, O.; Crespo, R.G.; Herrera-Viedma, E.; Fujita, H. Multilayer framework for botnet detection using machine learning algorithms. IEEE Access 2021, 9, 48753–48768. [Google Scholar] [CrossRef] [Scilit]
- Ramachandran, A.; Feamster, N.; Dagon, D. Revealing botnet membership using DNSBL counter-intelligence. In Proceedings of the 2nd Workshop on Steps to Reducing Unwanted Traffic on the Internet (SRUTI ’06), San Jose, CA, USA, 7 July 2006; pp. 49–54. [Google Scholar]
- Nagunwa, T.; Kearney, P.; Fouad, S. A machine learning approach for detecting fast flux phishing hostnames. J. Inf. Secur. Appl. 2022, 65, 103125. [Google Scholar] [CrossRef] [Scilit]
- Goldberg, D.E.; Holland, J.H. Genetic algorithms and machine learning. Mach. Learn. 1988, 3, 95–99. [Google Scholar] [CrossRef] [Scilit]
- Lin, H.T.; Lin, Y.Y.; Chiang, J.W. Genetic-based Real-time Fast-Flux Service Networks Detection. Comput. Netw. 2013, 57, 501–513. [Google Scholar] [CrossRef] [Scilit]
- Hosseini, S.; Nezhad, A.E.; Seilani, H. Botnet detection using negative selection algorithm, convolution neural network and classification methods. Evol. Syst. 2022, 13, 101–115. [Google Scholar] [CrossRef] [Scilit]
- Silveira, M.R.; Cansian, A.M.; Kobayashi, H.K. Semi-supervised approach for detecting malicious domains in TLDs in their first query. Int. J. Inf. Secur. 2025, 24, 80. [Google Scholar] [CrossRef] [Scilit]
- Shafi, M.; Lashkari, A.H.; Mohanty, H. Unveiling malicious DNS behavior profiling and generating benchmark dataset through application layer traffic analysis. Comput. Electr. Eng. 2024, 118, 109436. [Google Scholar] [CrossRef] [Scilit]
- Chandra, S.; Singh, M.; Gangopadhyaya, M.; Chakraborty, S.; Chowdhury, I. Fast Flux Network-Based Detection of Malicious DNS Domains. In Proceedings of the International Conference on Computational Intelligence, Data Science and Cloud Computing (IEM-ICDC 2025), Kolkata, India, 11–12 April 2025; Volume 1541. [Google Scholar] [CrossRef] [Scilit]
- Mahdavifar, S.; Maleki, N.; Lashkari, A.H.; Broda, M.; Razavi, A.H. Classifying Malicious Domains using DNS Traffic Analysis. In Proceedings of the 2021 IEEE Intl Conf on Dependable, Autonomic and Secure Computing (DASC), Online, 25–28 October 2021. [Google Scholar]
- VirusTotal. VirusTotal API v3: Domain Objects and Relationships. 2024. Available online: https://docs.virustotal.com/reference/domains-object (accessed on 1 September 2024).
- ISO 3166-1:2020; Codes for the Representation of Names of Countries and Their Subdivisions—Part 1: Country Code. International Organization for Standardization: Geneva, Switzerland, 2020.
- Maćkiewicz, A.; Ratajczak, W. Principal components analysis (PCA). Comput. Geosci. 1993, 19, 303–342. [Google Scholar] [CrossRef] [Scilit]
- Pedregosa, F.; Varoquaux, G.; Gramfort, A.; Michel, V.; Thirion, B.; Grisel, O.; Blondel, M.; Prettenhofer, P.; Weiss, R.; Dubourg, V.; et al. Scikit-learn: Machine Learning in Python. J. Mach. Learn. Res. 2011, 12, 2825–2830. [Google Scholar]











| Collection | Public | Fast-Flux Label | Raw Records | Scale and Focus |
|---|---|---|---|---|
| The dataset | Yes | Yes | Yes | 91,530 labeled domain records, 20 features, and about 8.5 GB of JSON, plus information on hosting spread, registration, and certificate history. |
| PASSVM [5] | No | Yes | No | Features from single DNS response messages plus local databases; online detection |
| Lombardo et al. [4] | No | Yes | No | One month of enterprise passive DNS with injected malware pcaps |
| Zang et al. [3] | No | Yes | No | Upper-hierarchy DNS traces, algorithmically generated names |
| Nagunwa et al. [18] | No | Yes | No | 56 features over fast-flux phishing hostnames, CDN and non-flux classes |
| CIC-Bell-DNS-2021 [25] | Yes | No | No | 400,000 benign and 13,011 malicious feature records labeled spam, phishing, or malware |
| BCCC-CIC-Bell-DNS-2024 [23] | Yes | No | Partly | DNS-flow features (120+) rebuilt from two earlier CIC datasets; exfiltration and attack categories |
| File Name | Size | Content Type | Description |
|---|---|---|---|
| Alexa1.rar | 1.97 GB | Legitimate domains | First partition of Alexa top-ranked domains for baseline comparison |
| Alexa2.rar | 2.31 GB | Legitimate domains | Second partition of Alexa top-ranked domains for baseline comparison |
| Alexa3.rar | 2.15 GB | Legitimate domains | Third partition of Alexa top-ranked domains for baseline comparison |
| FastFlux.rar | 2.12 GB | Fast-flux domains | Confirmed fast-flux domains with malicious behavior patterns |
| features.csv | 8.5 MB | Engineered features | Machine-learning-ready dataset with 91,530 records and 20 features |
| Relationship | Feature Derived | What the Records Themselves Support |
|---|---|---|
| Resolutions | Number of IPs, IPs without ASN, ASNs, Countries, Cities, and all three ratios | Address history with per-resolution dates and analysis statistics. The central file for fast-flux work |
| Subdomains | Number of Sub-Domains | Direct subdomains only, each with its own DNS history, WHOIS, certificate, and analysis records |
| Siblings | Number of Siblings | Names sharing an immediate parent; exposes the rest of a bulk-registered batch |
| Parent, Immediate Parent | Number of Parent/Immediate Parent | Separates registered domains from subdomains of one; carries the parent’s creation date and verdicts |
| Communicating files | Number of Communicated Files | Samples observed contacting the domain, with hashes, submission dates, and per-engine verdicts. Groups domains by the malware that reached them |
| Referrer files | Number of Referrer Files | Samples containing the domain as a literal string but not observed contacting it. Weaker evidence than a connection, and the two counts diverge sharply between classes |
| Historical SSL certificates | Number of Historical SSL Certificates | Issuer, subject, validity window and first-seen date. The windows show how long infrastructure stayed in place |
| Historical WHOIS | Number of Historical WHOIS | Registration snapshots with registrar, abuse contact and name servers; consecutive snapshots differ where ownership changed |
| Comments, related comments | None | Sparse free-text notes; occasionally name a campaign or malware family |
| Feature Name | Data Type | Value Range | Description | Category |
|---|---|---|---|---|
| Domain | String | Variable length | Domain name identifier | Identifier |
| Number of IPs | Integer | 1–440+ | Count of associated IP addresses | Network connectivity |
| Number of IPs without ASN | Integer | 0–N | Count of IPs lacking ASN information | Network connectivity |
| Number of ASNs | Integer | 2–194+ | Count of unique autonomous system numbers | Network connectivity |
| Number of Countries | Integer | 1–N | Count of countries hosting domain IPs | Geographic distribution |
| Number of Cities | Integer | 1–N | Count of cities hosting domain IPs | Geographic distribution |
| IPs to ASNs Ratio | Float | 1.0–N | Ratio of IP addresses to ASN count | Infrastructure metrics |
| IPs to Countries Ratio | Float | 1.0–N | Ratio of IP addresses to country count | Infrastructure metrics |
| IPs to Cities Ratio | Float | 1.0–N | Ratio of IP addresses to city count | Infrastructure metrics |
| Domain Length | Integer | 4–244 | Character count of the domain name | Domain characteristics |
| Domain Entropy | Float | 2.0–4.0+ | Information entropy of a domain name | Domain characteristics |
| TLD Type | Integer | 1–N | Top-level domain type classification | Domain characteristics |
| Has Private Owner | Boolean | True/False | Private WHOIS registration indicator | Registration characteristics |
| Number of Communicated Files | Integer | 0–N | Count of communicating files | Behavioral analysis |
| Number of Historical SSL Certificates | Integer | 0–N | Count of SSL certificate history records | Historical analysis |
| Number of Historical WHOIS | Integer | 0–N | Count of WHOIS history records | Historical analysis |
| Number of Parent/ Immediate Parent | Integer | 0–N | Count of parent domain relationships | Relationship analysis |
| Number of Referrer Files | Integer | 0–N | Count of referrer files | Traffic analysis |
| Number of Sub-Domains | Integer | 0–N | Count of discovered subdomains | Infrastructure analysis |
| Number of Siblings | Integer | 0–N | Count of sibling domains | Relationship analysis |
| Label | Integer | 0 or 1 | Classification label (0 = legitimate, 1 = fast-flux) | Target variable |
| # | Stage | What Was Done |
|---|---|---|
| 1 | Seed the malicious side | 80 confirmed fast-flux domains taken from published work [3,4,5] and from tweets reporting newly discovered domains |
| 2 | Active resolution | Each unique name resolved repeatedly with the Linux dig utility for just over two months; addresses read from the DNS response messages |
| 3 | VirusTotal expansion | Every observed address queried for the domains it had resolved to since April 2018, with the dates of those resolutions. The expansion yields 67,606 fast-flux domains |
| 4 | Seed the benign side | Alexa top-ranked list resolved the same way; we kept only domains returning five or more addresses, since a single A-record domain cannot exhibit flux and would make the comparison trivial. The expansion yields 23,924 legitimate domains |
| 5 | Relationship retrieval | For every domain and address, all VirusTotal relationships in Table 3 retrieved and stored unmodified |
| 6 | Network enrichment | Censys queried through its API for distinct ports, addresses, countries and cities; ASN and country attribution per address taken from a free IP geolocation database |
| 7 | Feature computation | The 20 features in Table 4 computed from the stored JSON, producing 91,530 labelled records |
| Feature | Shape of the Distribution | Figure |
|---|---|---|
| Number of IPs | Flux shows up here first: the benign half concentrates in the low categories while the fast-flux half spreads across the range and carries most of the “Other” bar | Figure 2 |
| Number of ASNs | Hosting spread across unrelated autonomous systems, the defining shape of fast flux. The classes separate clearly, though the forest leans more on the relationship counts | Figure 3 |
| Number of Countries | Separates the classes only in combination with the ASN count, because legitimate CDNs also span countries | Figure 4 |
| Number of Referrer Files | Diverges sharply between classes and ranks second in importance | Figure 5 |
| Number of Sub-Domains | Ranks first in importance; bulk-registered infrastructure shows a characteristic profile | Figure 6 |
| Domain Entropy | Often treated as a strong signal for generated names, but the two classes overlap heavily here | Figure 7 |
| IPs without ASN, and the IPs-to-ASNs, IPs-to-Countries and IPs-to-Cities ratios | Ratio features compress the same hosting-spread signal and are correlated with it | Figures S1–S4 |
| Number of Cities | Follows the country distribution, at lower reliability | Figure S5 |
| Domain Length, TLD Type, Has Private Owner | Name and registration properties; weak separators on their own | Figures S6–S8 |
| Communicated Files, Historical SSL Certificates, Historical WHOIS, Parent/Immediate Parent, Siblings | Behavioral and relationship counts; the parent count is close to binary, which is what makes it useful | Figures S9–S13 |
| Class | TP Rate | FP Rate | Precision | Recall | F1 Score |
|---|---|---|---|---|---|
| Safe | 0.9017 | 0.0193 | 0.9428 | 0.9017 | 0.9218 |
| Fast flux | 0.9807 | 0.0983 | 0.9658 | 0.9807 | 0.9731 |
| Work | Method | Reported | Evaluation Data |
|---|---|---|---|
| Al-Duwairi et al. [5] | SVM (RBF kernel) | 99.557% acc. | Authors’ own collection, not released |
| Nagunwa et al. [18] | Supervised ML, 56 features | 98.42% acc. | Authors’ own collection, not released |
| Ayo et al. [7] | Genetic rules with kNN | >99% acc. | Authors’ own botnet domains, not released |
| Silveira et al. [22] | Semi-supervised ensemble | 0.962 AUC | TLD registry data, not released |
| This baseline | Random forest, 19 features | 96.0% acc. | features.csv, public, protocol in Section 4.2 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Shatnawi, A.S.; Al-Duwairi, B.; Al-Shara, Z.; Almazari, M.M. Fast-Flux Dataset: Enhancing Cybersecurity Analysis and Defense. Data 2026, 11, 244. https://doi.org/10.3390/data11090244
Shatnawi AS, Al-Duwairi B, Al-Shara Z, Almazari MM. Fast-Flux Dataset: Enhancing Cybersecurity Analysis and Defense. Data. 2026; 11(9):244. https://doi.org/10.3390/data11090244
Chicago/Turabian StyleShatnawi, Ahmed S., Basheer Al-Duwairi, Zakarea Al-Shara, and Mahmoud M. Almazari. 2026. "Fast-Flux Dataset: Enhancing Cybersecurity Analysis and Defense" Data 11, no. 9: 244. https://doi.org/10.3390/data11090244
APA StyleShatnawi, A. S., Al-Duwairi, B., Al-Shara, Z., & Almazari, M. M. (2026). Fast-Flux Dataset: Enhancing Cybersecurity Analysis and Defense. Data, 11(9), 244. https://doi.org/10.3390/data11090244

