Real-time behavioral DGA detection through machine learning

被引:0
|
作者
Bisio, Federica [1 ]
Saeli, Salvatore [1 ]
Lombardo, Pierangelo [1 ]
Bernardi, Davide [1 ]
Perotti, Alan [1 ]
Massa, Danilo [1 ]
机构
[1] AizoOn Technol Consulting, Str Lionetto 6, I-10146 Turin, Italy
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
During the last years, the use of Domain Generation Algorithms (DGAs) has increased with the aim of improving the resiliency of communication between bots and Command and Control (C&C) infrastructure. In this paper, we report on an effective DGA-detection algorithm based on a single network monitoring. The first step of the proposed method is the detection of a bot looking for the C&C and thus querying many automatically generated domains. The second phase consists on the analysis of the resolved DNS requests in the same time interval. The linguistic and semantic features of the collected unresolved and resolved domains are then extracted in order to cluster them and identify the specific bot. Finally, clusters are analyzed in order to reduce false positives. The proposed solution has been evaluated over (1) an ad-hoc network where several known DGAs were injected and (2) the LAN of a company. In the first experiment, we deployed different families of malware employing several DGAs: all the malicious variants were detected by the proposed algorithm. In the real case scenario, the algorithm discovered an infected host in a 15-day-long experimental session, while producing a low false-positive rate during the same period.
引用
收藏
页数:6
相关论文
共 50 条
  • [41] Real-time botnet detection on large network bandwidths using machine learning
    Velasco-Mata, Javier
    Gonzalez-Castro, Victor
    Fidalgo, Eduardo
    Alegre, Enrique
    SCIENTIFIC REPORTS, 2023, 13 (01)
  • [42] A Real-Time Novelty Recognition Framework Based on Machine Learning for Fault Detection
    Albertin, Umberto
    Pedone, Giuseppe
    Brossa, Matilde
    Squillero, Giovanni
    Chiaberge, Marcello
    ALGORITHMS, 2023, 16 (02)
  • [43] Real-Time Drowsiness Detection System for Student Tracking using Machine Learning
    Borikar, Dilipkumar A.
    Dighorikar, Himani
    Ashtikar, Shridhar
    Bajaj, Ishika
    Gupta, Shivam
    INTERNATIONAL JOURNAL OF NEXT-GENERATION COMPUTING, 2023, 14 (01): : 246 - 254
  • [44] Windower: Feature Extraction for Real-Time DDoS Detection Using Machine Learning
    Goldschmidt, Patrik
    Kucera, Jan
    PROCEEDINGS OF 2024 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, NOMS 2024, 2024,
  • [45] Real-time detection of panoramic multitargets based on machine vision and deep learning
    Shen, Keyong
    Yang, Yang
    Zhang, Xiaoyu
    JOURNAL OF ELECTRONIC IMAGING, 2022, 31 (05)
  • [46] Real-time Incident Detection in Public Bus Systems Using Machine Learning
    Morais, Mayuri A.
    de Camargo, Raphael Y.
    2023 IEEE 26TH INTERNATIONAL CONFERENCE ON INTELLIGENT TRANSPORTATION SYSTEMS, ITSC, 2023, : 2044 - 2049
  • [47] Real-time Machine Learning for Symbol Detection in MIMO-OFDM Systems
    Liang, Yibin
    Li, Lianjun
    Yi, Yang
    Liu, Lingjia
    IEEE CONFERENCE ON COMPUTER COMMUNICATIONS (IEEE INFOCOM 2022), 2022, : 2068 - 2077
  • [48] Real-Time Cyber Attack Detection Over HoneyPi Using Machine Learning
    Alhan, Birkan
    Gonen, Serkan
    Karacayilmaz, Gokce
    Bariskan, Mehmet Ali
    Yilmaz, Ercan Nurcan
    TEHNICKI VJESNIK-TECHNICAL GAZETTE, 2022, 29 (04): : 1394 - 1401
  • [49] DESIGN OF REAL-TIME SYSTEM BASED ON MACHINE LEARNING FOR SNORING AND OSA DETECTION
    Luo, Huaiwen
    Zhang, Lu
    Zhou, Lianyu
    Lin, Xu
    Zhang, Zehuai
    Wang, Mingjiang
    2022 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2022, : 1156 - 1160
  • [50] Real-Time Hybrid Intrusion Detection System Using Machine Learning Techniques
    Dutt, Inadyuti
    Borah, Samarjeet
    Maitra, Indra Kanta
    Bhowmik, Kuharan
    Maity, Ayindrilla
    Das, Suvosmita
    ADVANCES IN COMMUNICATION, DEVICES AND NETWORKING, 2018, 462 : 885 - 894