Entropy and likelihood-based detection of DGA generated domain names and their families

被引:1
|
作者
Bhatia A. [1 ]
Vishvakarma D.K. [2 ]
Kaushik R. [3 ]
Agrawal A. [1 ]
机构
[1] Department of Computer Science, BITS, Rajasthan, Pilani
[2] Center for Artificial Intelligence and Robotics (CAIR), DRDO, Karnataka, Bangalore
[3] Department of Electronics and Communication Engineering, Maulana Azad National Institute of Technology, Madhya Pradesh, Bhopal
关键词
botnets; C&C server; command and control servers; domain generations algorithms; domain name system;
D O I
10.1504/IJSN.2022.125512
中图分类号
学科分类号
摘要
Botnet is a network of hosts (bots) infected by a common malware and controlled by command and control (C&C) servers. Once the malware is found in an infected host, it is easy to get the domain of its C&C server and block it. To counter such detection, many malware families use probabilistic algorithms, known as domain generation algorithms (DGAs), to generate domain names for the C&C servers. In this paper, we propose a probabilistic approach to identify the domain names that are likely to be generated by malware using DGAs. The proposed solution is based on the hypothesis that the entropy of human-generated domain names should be lesser than the entropy of DGA generated domain names. Results show that the percentage of false negatives in the detection of DGA generated domain names using the proposed method is less than 29% across 39 DGA families considered by us in our experimentation. Copyright © 2022 Inderscience Enterprises Ltd.
引用
收藏
页码:147 / 192
页数:45
相关论文
共 50 条
  • [21] Likelihood-Based Metric for Gibbs Sampling Turbo MIMO Detection
    Kobayashi, Yutaro
    Sanada, Yukitoshi
    IEICE TRANSACTIONS ON COMMUNICATIONS, 2021, E104B (09) : 1046 - 1053
  • [22] Likelihood-based inference in some continuous exponential families with unknown threshold parameters
    Dubinin, TM
    Vardeman, SB
    JOURNAL OF THE AMERICAN STATISTICAL ASSOCIATION, 2003, 98 (463) : 741 - 749
  • [23] SweeD: Likelihood-Based Detection of Selective Sweeps in Thousands of Genomes
    Pavlidis, Pavlos
    Zivkovic, Daniel
    Stamatakis, Alexandros
    Alachiotis, Nikolaos
    MOLECULAR BIOLOGY AND EVOLUTION, 2013, 30 (09) : 2224 - 2234
  • [24] A likelihood-based framework for quantification of brain receptor PET studies in the pixel domain
    Wang, ZJ
    Szabo, Z
    Han, Z
    Varga, J
    Liu, KJR
    2004 2ND IEEE INTERNATIONAL SYMPOSIUM ON BIOMEDICAL IMAGING: MACRO TO NANO, VOLS 1 AND 2, 2004, : 1381 - 1384
  • [25] Likelihood-based association analysis for nuclear families and unrelated subjects with missing genotype data
    Dudbridge, Frank
    HUMAN HEREDITY, 2008, 66 (02) : 87 - 98
  • [26] Detection method of domain names generated by DGAs based on semantic representation and deep neural network
    Xu, Congyuan
    Shen, Jizhong
    Du, Xin
    COMPUTERS & SECURITY, 2019, 85 : 77 - 88
  • [27] DGA domain name detection based on BiGRU-MCNN
    Chen, ChaoQuan
    Pan, LeiLei
    Xie, XiaoLan
    2019 4TH INTERNATIONAL CONFERENCE ON INTELLIGENT INFORMATION PROCESSING (ICIIP 2019), 2019, : 316 - 320
  • [28] Rapid penalized likelihood-based outlier detection via heteroskedasticity test
    Song, Yunquan
    Dong, Ping
    Wang, Xiuli
    Lin, Lu
    JOURNAL OF STATISTICAL COMPUTATION AND SIMULATION, 2017, 87 (06) : 1206 - 1229
  • [29] Likelihood-based testing of wavelet coefficients for damage detection in beam structures
    Shahsavari, Vahid
    Bastien, Josee
    Chouinard, Luc
    Clement, Antoine
    JOURNAL OF CIVIL STRUCTURAL HEALTH MONITORING, 2017, 7 (01) : 79 - 98
  • [30] Likelihood-based testing of wavelet coefficients for damage detection in beam structures
    Vahid Shahsavari
    Josée Bastien
    Luc Chouinard
    Antoine Clément
    Journal of Civil Structural Health Monitoring, 2017, 7 : 79 - 98