Real-Time Detection of Dictionary DGA Network Traffic Using Deep Learning

被引:0
|
作者
Highnam K. [1 ]
Puzio D. [2 ]
Luo S. [3 ]
Jennings N.R. [1 ]
机构
[1] Imperial College London, London
[2] Kensho Technologies, McLean, VA
[3] Tencent, Shenzhen
关键词
Botnets; Deep learning; Domain generation algorithm; Malware; Network security; Neural networks;
D O I
10.1007/s42979-021-00507-w
中图分类号
学科分类号
摘要
Botnets and malware continue to avoid detection by static rule engines when using domain generation algorithms (DGAs) for callouts to unique, dynamically generated web addresses. Common DGA detection techniques fail to reliably detect DGA variants that combine random dictionary words to create domain names that closely mirror legitimate domains. To combat this, we created a novel hybrid neural network, Bilbo the “bagging” model, that analyses domains and scores the likelihood they are generated by such algorithms and therefore are potentially malicious. Bilbo is the first parallel usage of a convolutional neural network (CNN) and a long short-term memory (LSTM) network for DGA detection. Our unique architecture is found to be the most consistent in performance in terms of AUC, F1 score, and accuracy when generalising across different dictionary DGA classification tasks compared to current state-of-the-art deep learning architectures. We validate using reverse-engineered dictionary DGA domains and detail our real-time implementation strategy for scoring real-world network logs within a large enterprise. In 4 h of actual network traffic, the model discovered at least five potential command-and-control networks that commercial vendor tools did not flag. © 2021, The Author(s).
引用
收藏
相关论文
共 50 条
  • [1] Real-Time Accident Detection in Traffic Surveillance Using Deep Learning
    Ghahremannezhad, Hadi
    Shi, Hang
    Liu, Chengjun
    2022 IEEE INTERNATIONAL CONFERENCE ON IMAGING SYSTEMS AND TECHNIQUES (IST 2022), 2022,
  • [2] Real-Time Detection and Recognition of Railway Traffic Signals Using Deep Learning
    Andrea Staino
    Akshat Suwalka
    Pabitra Mitra
    Biswajit Basu
    Journal of Big Data Analytics in Transportation, 2022, 4 (1): : 57 - 71
  • [3] Real-Time Barge Detection Using Traffic Cameras and Deep Learning on Inland Waterways
    Agorku, Geoffery
    Hernandez, Sarah
    Falquez, Maria
    Poddar, Subhadipto
    Amankwah-Nkyi, Kwadwo
    TRANSPORTATION RESEARCH RECORD, 2024,
  • [4] Real-Time Traffic Sign Recognition Using Deep Learning
    Shivayogi, Ananya Belagodu
    Dharmendra, Nehal Chakravarthy Matasagara
    Ramakrishna, Anala Maddur
    Subramanya, Kolala Nagaraju
    PERTANIKA JOURNAL OF SCIENCE AND TECHNOLOGY, 2023, 31 (01): : 137 - 148
  • [5] Predicting real-time traffic conflicts using deep learning
    Formosa, Nicolette
    Quddus, Mohammed
    Ison, Stephen
    Abdel-Aty, Mohamed
    Yuan, Jinghui
    ACCIDENT ANALYSIS AND PREVENTION, 2020, 136
  • [6] Network virtualization for real-time processing of object detection using deep learning
    Dae-Young Kim
    Ji-Hoon Park
    Youngchan Lee
    Seokhoon Kim
    Multimedia Tools and Applications, 2021, 80 : 35851 - 35869
  • [7] Network virtualization for real-time processing of object detection using deep learning
    Kim, Dae-Young
    Park, Ji-Hoon
    Lee, Youngchan
    Kim, Seokhoon
    MULTIMEDIA TOOLS AND APPLICATIONS, 2021, 80 (28-29) : 35851 - 35869
  • [8] Real-time behavioral DGA detection through machine learning
    Bisio, Federica
    Saeli, Salvatore
    Lombardo, Pierangelo
    Bernardi, Davide
    Perotti, Alan
    Massa, Danilo
    2017 INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY (ICCST), 2017,
  • [9] Real-time UAV Detection based on Deep Learning Network
    Hassan, Syed Ali
    Rahim, Tariq
    Shin, Soo Young
    2019 10TH INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY CONVERGENCE (ICTC): ICT CONVERGENCE LEADING THE AUTONOMOUS FUTURE, 2019, : 630 - 632
  • [10] Real-Time Traffic Sign Detection using Capsule Network
    Pari, Neelavathy S.
    Mohana, T.
    Akshaya, V
    2019 11TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING (ICOAC 2019), 2019, : 193 - 196