English
Related papers

Related papers: Exploiting Statistical and Structural Features for…

200 papers

Botnets and malware continue to avoid detection by static rules engines when using domain generation algorithms (DGAs) for callouts to unique, dynamically generated web addresses. Common DGA detection techniques fail to reliably detect DGA…

Cryptography and Security · Computer Science 2020-03-31 Kate Highnam , Domenic Puzio , Song Luo , Nicholas R. Jennings

Domain generation algorithms (DGAs) can be categorized into three types: zero-knowledge, partial-knowledge, and full-knowledge. While prior research merely focused on zero-knowledge and full-knowledge types, we characterize their…

Cryptography and Security · Computer Science 2022-12-09 Lihai Nie , Xiaoyang Shan , Laiping Zhao , Keqiu Li

Botnets represent a global problem and are responsible for causing large financial and operational damage to their victims. They are implemented with evasion in mind, and aim at hiding their architecture and authors, making them difficult…

Cryptography and Security · Computer Science 2014-11-03 Pedro Camelo , Joao Moura , Ludwig Krippahl

Domain generation algorithms (DGAs) prevent the connection between a botnet and its master from being blocked by generating a large number of domain names. Promising single-data-source approaches have been proposed for separating benign…

Cryptography and Security · Computer Science 2021-09-27 Arthur Drichel , Benedikt Holmes , Justus von Brandt , Ulrike Meyer

The goal of Domain Generation Algorithm (DGA) detection is to recognize infections with bot malware and is often done with help of Machine Learning approaches that classify non-resolving Domain Name System (DNS) traffic and are trained on…

Cryptography and Security · Computer Science 2021-10-13 Benedikt Holmes , Arthur Drichel , Ulrike Meyer

The Domain Name System (DNS) protocol plays a major role in today's Internet as it translates between website names and corresponding IP addresses. However, due to the lack of processes for data integrity and origin authentication, the DNS…

Cryptography and Security · Computer Science 2020-12-22 Abdallah Moubayed , MohammadNoor Injadat , Abdallah Shami

In this work, we conduct a comprehensive study on the robustness of domain generation algorithm (DGA) classifiers. We implement 32 white-box attacks, 19 of which are very effective and induce a false-negative rate (FNR) of $\approx$ 100\%…

Cryptography and Security · Computer Science 2024-04-10 Arthur Drichel , Marc Meyer , Ulrike Meyer

The persistent threat posed by malicious domain names in cyber-attacks underscores the urgent need for effective detection mechanisms. Traditional machine learning methods, while capable of identifying such domains, often suffer from high…

Cryptography and Security · Computer Science 2025-02-24 Daiki Chiba , Hiroki Nakano , Takashi Koide

This paper proposes a generic classification system designed to detect security threats based on the behavior of malware samples. The system relies on statistical features computed from proxy log fields to train detectors using a database…

Machine Learning · Statistics 2017-02-09 Lukas Machlica , Karel Bartos , Michal Sofka

Botnets are now a major source for many network attacks, such as DDoS attacks and spam. However, most traditional detection methods heavily rely on heuristically designed multi-stage detection criteria. In this paper, we consider the neural…

Cryptography and Security · Computer Science 2020-03-16 Jiawei Zhou , Zhiying Xu , Alexander M. Rush , Minlan Yu

Numerous malware families rely on domain generation algorithms (DGAs) to establish a connection to their command and control (C2) server. Counteracting DGAs, several machine learning classifiers have been proposed enabling the…

Cryptography and Security · Computer Science 2021-06-24 Arthur Drichel , Nils Faerber , Ulrike Meyer

Domain Generation Algorithms (DGAs) evolve continuously to evade botnet detection, posing a persistent challenge for dependable network defense. While deep learning-based detectors achieve strong performance under static conditions, they…

Cryptography and Security · Computer Science 2026-05-12 Chaeyoung Lee , Chaeri Jung , Seonghoon Jeong

Both enterprise and national firewalls filter network connections. For data forensics and botnet removal applications, it is important to establish the information source. In this paper, we describe a data transport layer which allows a…

Cryptography and Security · Computer Science 2017-04-04 Yu Fu , Zhe Jia , Lu Yu , Xingsi Zhong , Richard Brooks

As state-of-the-art language models continue to improve, the need for robust detection of machine-generated text becomes increasingly critical. However, current state-of-the-art machine text detectors struggle to adapt to new unseen domains…

Computation and Language · Computer Science 2025-05-21 Arihant Tripathi , Liam Dugan , Charis Gao , Maggie Huan , Emma Jin , Peter Zhang , David Zhang , Julia Zhao , Chris Callison-Burch

Domain Name System (DNS) is the backbone of the Internet. However, threat actors have abused the antiquated protocol to facilitate command-and-control (C2) actions, to tunnel, or to exfiltrate sensitive information in novel ways. The…

Cryptography and Security · Computer Science 2023-04-18 Adam Dorian Wong

IThe botnet is considered as a critical issue of the Internet due to its fast growing mechanism and affect. Recently, Botnets have utilized the DNS and query DNS server just like any legitimate hosts. In this case, it is difficult to…

Networking and Internet Architecture · Computer Science 2009-11-04 Ahmed M. Manasrah , Awsan Hasan , Omar Amer Abouabdalla , Sureswaran Ramadass

Mobile devices are frequent targets of eCrime threat actors through SMS spearphishing (smishing) links that leverage Domain Generation Algorithms (DGA) to rotate hostile infrastructure. Despite this, DGA research and evaluation largely…

Cryptography and Security · Computer Science 2026-03-04 Adam Dorian Wong , John D. Hastings

In recent years, vulnerable hosts and maliciously registered domains have been frequently involved in mobile attacks. In this paper, we explore the feasibility of detecting malicious domains visited on a cellular network based solely on…

Cryptography and Security · Computer Science 2015-06-15 Wei Wang , Kenneth Shirley

Domain generalization (DG) methods aim to develop models that generalize to settings where the test distribution is different from the training data. In this paper, we focus on the challenging problem of multi-source zero shot DG (MDG),…

Machine Learning · Computer Science 2022-11-07 Kowshik Thopalli , Sameeksha Katoch , Pavan Turaga , Jayaraman J. Thiagarajan

Network intrusion detection systems play a crucial role in the security strategy employed by organisations to detect and prevent cyberattacks. Such systems usually combine pattern detection signatures with anomaly detection techniques…

Cryptography and Security · Computer Science 2026-03-13 Massimiliano Altieri , Ronan Hamon , Roberto Corizzo , Michelangelo Ceci , Ignacio Sanchez