Real-time behavioral DGA detection through machine learning

被引:0
|
作者
Bisio, Federica [1 ]
Saeli, Salvatore [1 ]
Lombardo, Pierangelo [1 ]
Bernardi, Davide [1 ]
Perotti, Alan [1 ]
Massa, Danilo [1 ]
机构
[1] AizoOn Technol Consulting, Str Lionetto 6, I-10146 Turin, Italy
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
During the last years, the use of Domain Generation Algorithms (DGAs) has increased with the aim of improving the resiliency of communication between bots and Command and Control (C&C) infrastructure. In this paper, we report on an effective DGA-detection algorithm based on a single network monitoring. The first step of the proposed method is the detection of a bot looking for the C&C and thus querying many automatically generated domains. The second phase consists on the analysis of the resolved DNS requests in the same time interval. The linguistic and semantic features of the collected unresolved and resolved domains are then extracted in order to cluster them and identify the specific bot. Finally, clusters are analyzed in order to reduce false positives. The proposed solution has been evaluated over (1) an ad-hoc network where several known DGAs were injected and (2) the LAN of a company. In the first experiment, we deployed different families of malware employing several DGAs: all the malicious variants were detected by the proposed algorithm. In the real case scenario, the algorithm discovered an infected host in a 15-day-long experimental session, while producing a low false-positive rate during the same period.
引用
收藏
页数:6
相关论文
共 50 条
  • [21] An Automated Machine Learning Approach for Real-Time Fault Detection and Diagnosis
    Leite, Denis
    Martins, Aldonso, Jr.
    Rativa, Diego
    De Oliveira, Joao F. L.
    Maciel, Alexandre M. A.
    SENSORS, 2022, 22 (16)
  • [22] Real-time detection system for smartphone zombie based on machine learning
    Wada, Tomotaka
    Shikishima, Akito
    IEICE COMMUNICATIONS EXPRESS, 2020, 9 (07): : 268 - 273
  • [23] Real-time machine learning-based approach for pothole detection
    Egaji, Oche Alexander
    Evans, Gareth
    Griffiths, Mark Graham
    Islas, Gregory
    EXPERT SYSTEMS WITH APPLICATIONS, 2021, 184
  • [24] HarX: Real-time harassment detection tool using machine learning
    Rizwan, Kainat
    Babar, Sehar
    Nayab, Sania
    Hanif, Muhammad Kashif
    2021 INTERNATIONAL CONFERENCE OF MODERN TRENDS IN INFORMATION AND COMMUNICATION TECHNOLOGY INDUSTRY (MTICTI 2021), 2021, : 66 - 71
  • [25] Real-Time Detection System of Driver Distraction Using Machine Learning
    Tango, Fabio
    Botta, Marco
    IEEE TRANSACTIONS ON INTELLIGENT TRANSPORTATION SYSTEMS, 2013, 14 (02) : 894 - 905
  • [26] Machine Learning Based Real-Time Activity Detection System Design
    Eren, Kazim Kivanc
    Kucuk, Kerem
    2017 INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND ENGINEERING (UBMK), 2017, : 462 - 467
  • [27] Real-time PV Fault Detection using Embedded Machine Learning
    Pujara, Deep
    Ramirez, David
    Tepedelenlioglu, Cihan
    Srinivasan, Devarajan
    Spanias, Andreas
    2024 IEEE 7TH INTERNATIONAL CONFERENCE ON INDUSTRIAL CYBER-PHYSICAL SYSTEMS, ICPS 2024, 2024,
  • [28] SUPPORTING COMPLEX REAL-TIME DECISION-MAKING THROUGH MACHINE LEARNING
    CHATURVEDI, AR
    HUTCHINSON, GK
    NAZARETH, DL
    DECISION SUPPORT SYSTEMS, 1993, 10 (02) : 213 - 233
  • [29] Real-Time Anomaly Detection Framework for Many-Core Router through Machine-Learning Techniques
    Kulkarni, Amey
    Pino, Youngok
    French, Matthew
    Mohsenin, Tinoosh
    ACM JOURNAL ON EMERGING TECHNOLOGIES IN COMPUTING SYSTEMS, 2016, 13 (01)
  • [30] Machine Learning Application for Real-Time Simulator
    Hadadi, Azadeh
    Chardonnet, Jean-Remy
    Guillet, Christophe
    Ovtcharova, Jivka
    PROCEEDINGS OF THE 2024 9TH INTERNATIONAL CONFERENCE ON MACHINE LEARNING TECHNOLOGIES, ICMLT 2024, 2024, : 1 - 5