首页> 外文期刊>Computers & Security >MaldomDetector: A system for detecting algorithmically generated domain names with machine learning
【24h】

MaldomDetector: A system for detecting algorithmically generated domain names with machine learning

机译:MaldomDetector:一种用于通过机器学习检测算法生成的域名的系统

获取原文
获取原文并翻译 | 示例

摘要

One of the leading problems in cyber security at present is the unceasing emergence of sophisticated attacks, such as botnets and ransomware, that rely heavily on Command and Control (C&C) channels to conduct their malicious activities remotely. To avoid channel detection, attackers constantly try to create different covert communication techniques. One such technique is Domain Generation Algorithm (DGA), which allows malware to generate numerous domain names until it finds its corresponding C&C server. It is highly resilient to detection systems and reverse engineering, while allowing the C&C server to have several redundant domain names. This paper presents a malicious domain name detection system, MaldomDetector, which is based on machine learning. It is capable of detecting DGA-based communications and circumventing the attack before it makes any successful connection with the C&C server, using only domain name's characters. MaldomDetector uses a set of easy-to-compute and language-independent features in addition to a deterministic algorithm to detect malicious domains. The experimental results demonstrate that MaldomDetector can operate efficiently as a first alarm to detect DGA-based domains of malware families while maintaining high detection accuracy.
机译:目前网络安全的领先问题之一是依赖于指挥和控制(C&C)渠道的复杂攻击,如僵尸网络和赎金软件的不断产生,以便远程进行恶意活动。为避免频道检测,攻击者不断尝试创建不同的隐蔽通信技术。一种这样的技术是域生成算法(DGA),它允许恶意软件在找到其相应的C&C服务器之前生成众多域名。它是对检测系统和逆向工程的强烈弹性,同时允许C&C服务器具有多个冗余域名。本文介绍了一个恶意域名检测系统,MaldomDetector,基于机器学习。它能够在使用仅使用域名的字符的C&C服务器进行任何成功连接之前检测基于DGA的通信并避免攻击。除了确定性算法之外,MaldomDetector还使用一组易于计算和独立的功能来检测恶意域。实验结果表明,MaldomDetector可以有效地作为第一个警报操作,以检测恶意软件系列的基于DGA的基础域,同时保持高检测精度。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号