Real-time behavioral DGA detection through machine learning

被引:0
|
作者
Bisio, Federica [1 ]
Saeli, Salvatore [1 ]
Lombardo, Pierangelo [1 ]
Bernardi, Davide [1 ]
Perotti, Alan [1 ]
Massa, Danilo [1 ]
机构
[1] AizoOn Technol Consulting, Str Lionetto 6, I-10146 Turin, Italy
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
During the last years, the use of Domain Generation Algorithms (DGAs) has increased with the aim of improving the resiliency of communication between bots and Command and Control (C&C) infrastructure. In this paper, we report on an effective DGA-detection algorithm based on a single network monitoring. The first step of the proposed method is the detection of a bot looking for the C&C and thus querying many automatically generated domains. The second phase consists on the analysis of the resolved DNS requests in the same time interval. The linguistic and semantic features of the collected unresolved and resolved domains are then extracted in order to cluster them and identify the specific bot. Finally, clusters are analyzed in order to reduce false positives. The proposed solution has been evaluated over (1) an ad-hoc network where several known DGAs were injected and (2) the LAN of a company. In the first experiment, we deployed different families of malware employing several DGAs: all the malicious variants were detected by the proposed algorithm. In the real case scenario, the algorithm discovered an infected host in a 15-day-long experimental session, while producing a low false-positive rate during the same period.
引用
收藏
页数:6
相关论文
共 50 条
  • [1] Adaptive Real-time Trojan Detection Framework through Machine Learning
    Kulkarni, Amey
    Pino, Youngok
    Mohsenin, Tinoosh
    PROCEEDINGS OF THE 2016 IEEE INTERNATIONAL SYMPOSIUM ON HARDWARE ORIENTED SECURITY AND TRUST (HOST), 2016, : 120 - 123
  • [2] Real-Time Detection of Fake-Shops through Machine Learning
    Beltzung, Louise
    Lindley, Andrew
    Dinica, Olivia
    Hermann, Nadin
    Lindner, Raphaela
    2020 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2020, : 2254 - 2263
  • [3] Machine learning for real-time remote detection
    Labbe, Benjamin
    Fournier, Jerome
    Henaff, Gilles
    Bascle, Benedicte
    Canu, Stephane
    OPTICS AND PHOTONICS FOR COUNTERTERRORISM AND CRIME FIGHTING VI AND OPTICAL MATERIALS IN DEFENCE SYSTEMS TECHNOLOGY VII, 2010, 7838
  • [4] Real-Time Detection of Dictionary DGA Network Traffic Using Deep Learning
    Highnam K.
    Puzio D.
    Luo S.
    Jennings N.R.
    SN Computer Science, 2021, 2 (2)
  • [5] Automated real-time anomaly detection of temperature sensors through machine-learning
    Nayak, Debanjana
    Perros, Harry
    INTERNATIONAL JOURNAL OF SENSOR NETWORKS, 2020, 34 (03) : 137 - 152
  • [6] A MACHINE LEARNING FRAMEWORK FOR REAL-TIME TRAFFIC DENSITY DETECTION
    Chen, Jing
    Tan, Evan
    Li, Zhidong
    INTERNATIONAL JOURNAL OF PATTERN RECOGNITION AND ARTIFICIAL INTELLIGENCE, 2009, 23 (07) : 1265 - 1284
  • [7] Real-Time Slip Detection and Control Using Machine Learning
    Pereira Tavares, Alexandre Henrique
    Oliveira, S. R. J.
    XXVII BRAZILIAN CONGRESS ON BIOMEDICAL ENGINEERING, CBEB 2020, 2022, : 1363 - 1369
  • [8] Real-Time Facial Emotion Detection Through the Use of Machine Learning and On-Edge Computing
    Dowd, Ashley
    Tonekaboni, Navid Hashemi
    2022 21ST IEEE INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND APPLICATIONS, ICMLA, 2022, : 444 - 448
  • [9] Real-time pavement temperature prediction through ensemble machine learning
    Kebede, Yared Bitew
    Yang, Ming-Der
    Huang, Chien-Wei
    ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2024, 135
  • [10] A REAL-TIME SHEEP COUNTING DETECTION SYSTEM BASED ON MACHINE LEARNING
    Deng, Xuefeng
    Zhang, Song
    Shao, Yi
    Yan, Xiaoli
    INMATEH-AGRICULTURAL ENGINEERING, 2022, 67 (02): : 85 - 94