首页> 外国专利> Identifying malware communications with DGA generated domains by discriminative learning

Identifying malware communications with DGA generated domains by discriminative learning

机译:通过判别学习识别与DGA生成域的恶意软件通信

摘要

Techniques are presented to identify malware communication with domain generation algorithm (DGA) generated domains. Sample domain names are obtained and labeled as DGA domains, non-DGA domains or suspicious domains. A classifier is trained in a first stage based on the sample domain names. Sample proxy logs including proxy logs of DGA domains and proxy logs of non-DGA domains are obtained to train the classifier in a second stage based on the plurality of sample domain names and the plurality of sample proxy logs. Live traffic proxy logs are obtained and the classifier is tested by classifying the live traffic proxy logs as DGA proxy logs, and the classifier is forwarded to a second computing device to identify network communication of a third computing device as malware network communication with DGA domains via a network interface unit of the third computing device based on the trained and tested classifier.
机译:提出了利用域生成算法(DGA)生成的域识别恶意软件通信的技术。样本域名被获取并标记为DGA域,非DGA域或可疑域。在第一阶段,基于样本域名对分类器进行训练。基于多个样本域名和多个样本代理日志,获取包括DGA域的代理日志和非DGA域的代理日志的样本代理日志,以在第二阶段训练分类器。通过将实时流量代理日志分类为DGA代理日志来获取实时流量代理日志并测试分类器,并将分类器转发到第二计算设备,以将第三计算设备的网络通信识别为经由DGA域与DGA域进行的恶意软件网络通信。基于训练和测试的分类器的第三计算设备的网络接口单元。

著录项

  • 公开/公告号US9781139B2

    专利类型

  • 公开/公告日2017-10-03

    原文格式PDF

  • 申请/专利权人 CISCO TECHNOLOGY INC.;

    申请/专利号US201514806236

  • 申请日2015-07-22

  • 分类号G06F11/00;G06F12/14;G06F12/16;G08B23/00;H04L29/06;G06N99/00;H04L29/12;

  • 国家 US

  • 入库时间 2022-08-21 13:44:20

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号