Real-Time Detection of Dictionary DGA Network Traffic Using Deep Learning

被引:0
作者
Highnam K. [1 ]
Puzio D. [2 ]
Luo S. [3 ]
Jennings N.R. [1 ]
机构
[1] Imperial College London, London
[2] Kensho Technologies, McLean, VA
[3] Tencent, Shenzhen
关键词
Botnets; Deep learning; Domain generation algorithm; Malware; Network security; Neural networks;
D O I
10.1007/s42979-021-00507-w
中图分类号
学科分类号
摘要
Botnets and malware continue to avoid detection by static rule engines when using domain generation algorithms (DGAs) for callouts to unique, dynamically generated web addresses. Common DGA detection techniques fail to reliably detect DGA variants that combine random dictionary words to create domain names that closely mirror legitimate domains. To combat this, we created a novel hybrid neural network, Bilbo the “bagging” model, that analyses domains and scores the likelihood they are generated by such algorithms and therefore are potentially malicious. Bilbo is the first parallel usage of a convolutional neural network (CNN) and a long short-term memory (LSTM) network for DGA detection. Our unique architecture is found to be the most consistent in performance in terms of AUC, F1 score, and accuracy when generalising across different dictionary DGA classification tasks compared to current state-of-the-art deep learning architectures. We validate using reverse-engineered dictionary DGA domains and detail our real-time implementation strategy for scoring real-world network logs within a large enterprise. In 4 h of actual network traffic, the model discovered at least five potential command-and-control networks that commercial vendor tools did not flag. © 2021, The Author(s).
引用
收藏
相关论文
共 50 条
  • [31] A Real-Time Parking Space Occupancy Detection Using Deep Learning Model
    Prova, Raktim Raihan
    Shinha, Title
    Pew, Anamika Basak
    Rahman, Rashedur M.
    2022 IEEE INTERNATIONAL IOT, ELECTRONICS AND MECHATRONICS CONFERENCE (IEMTRONICS), 2022, : 51 - 57
  • [32] Real-Time Automatic Ejection Fraction and Foreshortening Detection Using Deep Learning
    Smistad, Erik
    Ostvik, Andreas
    Salte, Ivar Mjaland
    Melichova, Daniela
    Nguyen, Thuy Mi
    Haugaa, Kristina
    Brunvand, Harald
    Edvardsen, Thor
    Leclerc, Sarah
    Bernard, Olivier
    Grenne, Bjornar
    Lovstakken, Lasse
    IEEE TRANSACTIONS ON ULTRASONICS FERROELECTRICS AND FREQUENCY CONTROL, 2020, 67 (12) : 2595 - 2604
  • [33] Real-time fire and smoke detection for mobile devices using deep learning
    Safak, Emre
    Barisci, Necaattin
    JOURNAL OF THE FACULTY OF ENGINEERING AND ARCHITECTURE OF GAZI UNIVERSITY, 2023, 38 (04): : 2179 - 2190
  • [34] Real-Time Vehicle Detection using Deep Learning Scheme on Embedded System
    Shin, Ju-Seok
    Kim, Ung-Tae
    Lee, Deok-Kwon
    Park, Sang-Jun
    Oh, Se-Jin
    Yun, Tae-Jin
    2017 NINTH INTERNATIONAL CONFERENCE ON UBIQUITOUS AND FUTURE NETWORKS (ICUFN 2017), 2017, : 272 - 274
  • [35] Efficient real-time defect detection for spillway tunnel using deep learning
    Feng, Chuncheng
    Zhang, Hua
    Li, Yonglong
    Wang, Shuang
    Wang, Haoran
    JOURNAL OF REAL-TIME IMAGE PROCESSING, 2021, 18 (06) : 2377 - 2387
  • [36] Real-Time Detection of Strawberry Ripeness Using Augmented Reality and Deep Learning
    Chai, Jackey J. K.
    Xu, Jun-Li
    O'Sullivan, Carol
    SENSORS, 2023, 23 (17)
  • [37] Spatiotemporal Anomaly Detection Using Deep Learning for Real-Time Video Surveillance
    Nawaratne, Rashmika
    Alahakoon, Damminda
    De Silva, Daswin
    Yu, Xinghuo
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2020, 16 (01) : 393 - 402
  • [38] Real-Time Psychological Stress Detection According to ECG Using Deep Learning
    Zhang, Pengfei
    Li, Fenghua
    Zhao, Rongjian
    Zhou, Ruishi
    Du, Lidong
    Zhao, Zhan
    Chen, Xianxiang
    Fang, Zhen
    APPLIED SCIENCES-BASEL, 2021, 11 (09):
  • [39] Real-Time Polyp Detection, Localization and Segmentation in Colonoscopy Using Deep Learning
    Jha, Debesh
    Ali, Sharib
    Tomar, Nikhil Kumar
    Johansen, Havard D.
    Johansen, Dag
    Rittscher, Jens
    Riegler, Michael A.
    Halvorsen, Pal
    IEEE ACCESS, 2021, 9 : 40496 - 40510
  • [40] A real-time forest fire and smoke detection system using deep learning
    Mohammed, Raghad K.
    INTERNATIONAL JOURNAL OF NONLINEAR ANALYSIS AND APPLICATIONS, 2022, 13 (01): : 2053 - 2063