Real-Time Detection of Dictionary DGA Network Traffic Using Deep Learning

被引:0
|
作者
Highnam K. [1 ]
Puzio D. [2 ]
Luo S. [3 ]
Jennings N.R. [1 ]
机构
[1] Imperial College London, London
[2] Kensho Technologies, McLean, VA
[3] Tencent, Shenzhen
关键词
Botnets; Deep learning; Domain generation algorithm; Malware; Network security; Neural networks;
D O I
10.1007/s42979-021-00507-w
中图分类号
学科分类号
摘要
Botnets and malware continue to avoid detection by static rule engines when using domain generation algorithms (DGAs) for callouts to unique, dynamically generated web addresses. Common DGA detection techniques fail to reliably detect DGA variants that combine random dictionary words to create domain names that closely mirror legitimate domains. To combat this, we created a novel hybrid neural network, Bilbo the “bagging” model, that analyses domains and scores the likelihood they are generated by such algorithms and therefore are potentially malicious. Bilbo is the first parallel usage of a convolutional neural network (CNN) and a long short-term memory (LSTM) network for DGA detection. Our unique architecture is found to be the most consistent in performance in terms of AUC, F1 score, and accuracy when generalising across different dictionary DGA classification tasks compared to current state-of-the-art deep learning architectures. We validate using reverse-engineered dictionary DGA domains and detail our real-time implementation strategy for scoring real-world network logs within a large enterprise. In 4 h of actual network traffic, the model discovered at least five potential command-and-control networks that commercial vendor tools did not flag. © 2021, The Author(s).
引用
收藏
相关论文
共 50 条
  • [11] Cloud-based Real-time Network Intrusion Detection Using Deep Learning
    Parampottupadam, Santhosh
    Moldovann, Arghir-Nicolae
    2018 INTERNATIONAL CONFERENCE ON CYBER SECURITY AND PROTECTION OF DIGITAL SERVICES (CYBER SECURITY), 2018,
  • [12] Real-Time Fall Detection Using Wideband Radar and a Lightweight Deep Learning Network
    Cao, Binyue
    Ping, Qinwen
    Liu, Bingwen
    Nian, Yongjian
    He, Mi
    IEEE SENSORS JOURNAL, 2024, 24 (20) : 33682 - 33693
  • [13] Real Time Traffic Light Detection and Classification using Deep Learning
    Ennahhal, Zakaria
    Berrada, Ismail
    Fardousse, Khalid
    2019 INTERNATIONAL CONFERENCE ON WIRELESS NETWORKS AND MOBILE COMMUNICATIONS (WINCOM), 2019, : 116 - 122
  • [14] Real-time traffic incident detection based on a hybrid deep learning model
    Li, Linchao
    Lin, Yi
    Du, Bowen
    Yang, Fan
    Ran, Bin
    TRANSPORTMETRICA A-TRANSPORT SCIENCE, 2022, 18 (01) : 78 - 98
  • [15] Real-Time Stroke Detection Using Deep Learning and Federated Learning
    Elhanashi, Abdussalam
    Dini, Pierpaolo
    Saponara, Sergio
    Zheng, Qinghe
    Alsharif, Ibrahim
    REAL-TIME PROCESSING OF IMAGE, DEPTH, AND VIDEO INFORMATION 2024, 2024, 13000
  • [16] Real-time defect detection network for polarizer based on deep learning
    Ruizhen Liu
    Zhiyi Sun
    Anhong Wang
    Kai Yang
    Yin Wang
    Qianlai Sun
    Journal of Intelligent Manufacturing, 2020, 31 : 1813 - 1823
  • [17] A real-time deep learning network for ship detection in SAR images
    Zhou, Wenxue
    Zhang, Huachun
    SIGNAL IMAGE AND VIDEO PROCESSING, 2024, 18 (02) : 1893 - 1899
  • [18] Real-time defect detection network for polarizer based on deep learning
    Liu, Ruizhen
    Sun, Zhiyi
    Wang, Anhong
    Yang, Kai
    Wang, Yin
    Sun, Qianlai
    JOURNAL OF INTELLIGENT MANUFACTURING, 2020, 31 (08) : 1813 - 1823
  • [19] Real-time Driver Drowsiness Detection using Deep Learning
    Dipu M.T.A.
    Hossain S.S.
    Arafat Y.
    Rafiq F.B.
    Dipu, Md. Tanvir Ahammed, 1600, Science and Information Organization (12): : 844 - 850
  • [20] A real-time deep learning network for ship detection in SAR images
    Wenxue Zhou
    Huachun Zhang
    Signal, Image and Video Processing, 2024, 18 : 1893 - 1899