TY - GEN
T1 - AGDB
T2 - 7th IEEE International Conference on Data Science in Cyberspace, DSC 2022
AU - Zhai, You
AU - Dong, Hao
AU - Li, Zhoujun
AU - Yang, Liqun
AU - He, Longtao
N1 - Publisher Copyright:
© 2022 IEEE.
PY - 2022
Y1 - 2022
N2 - Botnets are starting to use domain generation algorithms (DGAs) extensively to enhance the stealth of command and control (C&C) communications between C&C servers and bots. Domains generated by DGAs are called algorithmically generated domains (AGDs), which also known as malicious domains. Detection of AGDs is a crucial element for fighting botnets and security researchers have proposed a variety of DGA detection methods. In order to avoid the detection of DGA detectors, various types of DGAs are continuously updated. Among them, the dictionary-based malicious domain, with strong camouflage, is the most advanced DGA representative and the previous detection methods are very ineffective on this type of malicious domain. To solve this problem, we explore the dictionary-based malicious domain generation algorithm, and propose, AGDB, a dictionary-based malicious domain detection method based on representation fusion, which combines features extracted from the context-based malicious domain detection model with features extracted from the graph-based malicious domain detection model. The experimental results show that the detection method based on representation fusion significantly outperforms the existing methods in terms of precision and recall.
AB - Botnets are starting to use domain generation algorithms (DGAs) extensively to enhance the stealth of command and control (C&C) communications between C&C servers and bots. Domains generated by DGAs are called algorithmically generated domains (AGDs), which also known as malicious domains. Detection of AGDs is a crucial element for fighting botnets and security researchers have proposed a variety of DGA detection methods. In order to avoid the detection of DGA detectors, various types of DGAs are continuously updated. Among them, the dictionary-based malicious domain, with strong camouflage, is the most advanced DGA representative and the previous detection methods are very ineffective on this type of malicious domain. To solve this problem, we explore the dictionary-based malicious domain generation algorithm, and propose, AGDB, a dictionary-based malicious domain detection method based on representation fusion, which combines features extracted from the context-based malicious domain detection model with features extracted from the graph-based malicious domain detection model. The experimental results show that the detection method based on representation fusion significantly outperforms the existing methods in terms of precision and recall.
KW - BERT
KW - Botnet
KW - Domain Generation Algorithm
KW - Representation Fusion
UR - https://www.scopus.com/pages/publications/85141416053
U2 - 10.1109/DSC55868.2022.00064
DO - 10.1109/DSC55868.2022.00064
M3 - 会议稿件
AN - SCOPUS:85141416053
T3 - Proceedings - 2022 7th IEEE International Conference on Data Science in Cyberspace, DSC 2022
SP - 420
EP - 425
BT - Proceedings - 2022 7th IEEE International Conference on Data Science in Cyberspace, DSC 2022
PB - Institute of Electrical and Electronics Engineers Inc.
Y2 - 11 July 2022 through 13 July 2022
ER -