Real-time behavioral DGA detection through machine learning

被引:0
|
作者
Bisio, Federica [1 ]
Saeli, Salvatore [1 ]
Lombardo, Pierangelo [1 ]
Bernardi, Davide [1 ]
Perotti, Alan [1 ]
Massa, Danilo [1 ]
机构
[1] AizoOn Technol Consulting, Str Lionetto 6, I-10146 Turin, Italy
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
During the last years, the use of Domain Generation Algorithms (DGAs) has increased with the aim of improving the resiliency of communication between bots and Command and Control (C&C) infrastructure. In this paper, we report on an effective DGA-detection algorithm based on a single network monitoring. The first step of the proposed method is the detection of a bot looking for the C&C and thus querying many automatically generated domains. The second phase consists on the analysis of the resolved DNS requests in the same time interval. The linguistic and semantic features of the collected unresolved and resolved domains are then extracted in order to cluster them and identify the specific bot. Finally, clusters are analyzed in order to reduce false positives. The proposed solution has been evaluated over (1) an ad-hoc network where several known DGAs were injected and (2) the LAN of a company. In the first experiment, we deployed different families of malware employing several DGAs: all the malicious variants were detected by the proposed algorithm. In the real case scenario, the algorithm discovered an infected host in a 15-day-long experimental session, while producing a low false-positive rate during the same period.
引用
收藏
页数:6
相关论文
共 50 条
  • [31] Real-Time Postural Disturbance Detection Through Sensor Fusion of EEG and Motion Data Using Machine Learning
    Wang, Zhuo
    Noah, Avia
    Graci, Valentina
    Keshner, Emily A.
    Griffith, Madeline
    Seacrist, Thomas
    Burns, John
    Gal, Ohad
    Guez, Allon
    SENSORS, 2024, 24 (23)
  • [32] Enhancing MOOCs through Real-time Learner Engagement and Emotion Detection Using Computer Vision and Machine Learning
    Mrayhi, Salwa
    Khribi, Mohamed Koutheair
    Jemni, Mohamed
    2024 IEEE INTERNATIONAL CONFERENCE ON ADVANCED LEARNING TECHNOLOGIES, ICALT 2024, 2024, : 1 - 2
  • [33] Learning system in real-time machine vision
    Li, Wenbin
    Lv, Zhihan
    Cosker, Darren
    Yang, Yongliang
    NEUROCOMPUTING, 2018, 288 : 1 - 2
  • [34] A Compositional Approach for Real-Time Machine Learning
    Allen, Nathan
    Raje, Yash
    Ro, Jin Woo
    Roop, Partha
    17TH ACM-IEEE INTERNATIONAL CONFERENCE ON FORMAL METHODS AND MODELS FOR SYSTEM DESIGN (MEMOCODE), 2019,
  • [35] Real-Time Machine Learning: The Missing Pieces
    Nishihara, Robert
    Moritz, Philipp
    Wang, Stephanie
    Tumanov, Alexey
    Paul, William
    Schleier-Smith, Johann
    Liaw, Richard
    Niknami, Mehrdad
    Jordan, Michael, I
    Stoica, Ion
    PROCEEDINGS OF THE 16TH WORKSHOP ON HOT TOPICS IN OPERATING SYSTEMS (HOTOS 2017), 2017, : 106 - 110
  • [36] Panic Detection Using Machine Learning and Real-Time Biometric and Spatiotemporal Data
    Lazarou, Ilias
    Kesidis, Anastasios L.
    Hloupis, George
    Tsatsaris, Andreas
    ISPRS INTERNATIONAL JOURNAL OF GEO-INFORMATION, 2022, 11 (11)
  • [37] Machine Learning-Based Real-Time Fraud Detection in Financial Transactions
    Manoharan, Geetha
    Dharmaraj, A.
    Sheela, S. Christina
    Naidu, Kanchan
    Chavva, Madhu
    Chaudhary, Jitendra Kumar
    2024 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATION AND APPLIED INFORMATICS, ACCAI 2024, 2024,
  • [38] Real-time botnet detection on large network bandwidths using machine learning
    Javier Velasco-Mata
    Víctor González-Castro
    Eduardo Fidalgo
    Enrique Alegre
    Scientific Reports, 13
  • [39] A REAL-TIME THROUGH-WALL DETECTION BASED ON SUPPORT VECTOR MACHINE
    Wang, F. -F.
    Zhang, Y. -R.
    JOURNAL OF ELECTROMAGNETIC WAVES AND APPLICATIONS, 2011, 25 (01) : 75 - 84
  • [40] Machine Tools Anomaly Detection Through Nearly Real-Time Data Analysis
    Herranz, Gorka
    Antolinez, Alfonso
    Escartin, Javier
    Arregi, Amaia
    Kepa Gerrikagoitia, Jon
    JOURNAL OF MANUFACTURING AND MATERIALS PROCESSING, 2019, 3 (04):