返回
MaldomDetector: A system for detecting algorithmically generated domain names with machine learning
DOI:10.1016/j.cose.2020.101787.png)
摘要
En 中文
One of the leading problems in cyber security at present is the unceasing emergence of sophisticated attacks, such as botnets and ransomware, that rely heavily on Command and Control (C&C) channels to conduct their malicious activities remotely. To avoid channel detection, attackers constantly try to create different covert communication techniques. One such technique is Domain Generation Algorithm (DGA), which allows malware to generate numerous domain names until it finds its corresponding C&C server. It is highly resilient to detection systems and reverse engineering, while allowing the C&C server to have several redundant domain names. This paper presents a malicious domain name detection system, Mal-domDetector, which is based on machine learning. It is capable of detecting DGA-based communications and circumventing the attack before it makes any successful connection with the C&C server, using only domain name's characters. MaldomDetector uses a set of easy-to-compute and language-independent features in addition to a deterministic algorithm to detect malicious domains. The experimental results demonstrate that MaldomDetector can operate efficiently as a first alarm to detect DGA-based domains of malware families while maintaining high detection accuracy. (C) 2020 The Authors. Published by Elsevier Ltd.
Keyword:
Network security
Intrusion detection
Machine learning
Command and control
Domain Generation Algorithm (DGA)
DNS
Domain name
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
C
IF:
5.4
论文数:
4.6K
被引数:
1.4W
机构
引用论文
Detection method of domain names generated by DGAs based on semantic representation and deep neural network
COMPUTERS & SECURITY
IF5.4
Detecting Algorithmically Generated Domain-Flux Attacks With DNS Traffic Analysis通过DNS流量分析检测算法生成的域流量攻击
A Multi-Classifier Network-Based Crypto Ransomware Detection System: A Case Study of Locky Ransomware基于多分类器网络的加密勒索软件检测系统 -- 以Locky勒索软件为例
IEEE ACCESS
IF3.6
A LSTM based framework for handling multiclass imbalance in DGA botnet detection基于LSTM的DGA僵尸网络检测中多类不平衡处理框架
NEUROCOMPUTING
IF6.5
没有更多内容

