English
Related papers

Related papers: Fine-tuning Large Language Models for DGA and DNS …

200 papers

This work analyzes the use of large language models (LLMs) for detecting domain generation algorithms (DGAs). We perform a detailed evaluation of two important techniques: In-Context Learning (ICL) and Supervised Fine-Tuning (SFT), showing…

Computation and Language · Computer Science 2024-11-06 Reynier Leyva La O , Carlos A. Catania , Tatiana Parlanti

Various families of malware use domain generation algorithms (DGAs) to generate a large number of pseudo-random domain names to connect to a command and control (C&C) server. In order to block DGA C&C traffic, security organizations must…

Cryptography and Security · Computer Science 2016-11-04 Jonathan Woodbridge , Hyrum S. Anderson , Anjum Ahuja , Daniel Grant

Modern malware families often rely on domain-generation algorithms (DGAs) to determine rendezvous points to their command-and-control server. Traditional defence strategies (such as blacklisting domains or IP addresses) are inadequate…

Cryptography and Security · Computer Science 2017-09-22 Pierre Lison , Vasileios Mavroeidis

The sophistication of modern malware, specifically regarding communication with Command and Control (C2) servers, has rendered static blacklist-based defenses obsolete. The use of Domain Generation Algorithms (DGA) allows attackers to…

Machine Learning · Computer Science 2025-12-10 Maria Milena Araujo Felix

Domain Generation Algorithms (DGAs) are used by adversaries to establish Command and Control (C\&C) server communications during cyber attacks. Blacklists of known/identified C\&C domains are often used as one of the defense mechanisms.…

Cryptography and Security · Computer Science 2021-01-05 Ibrahim Yilmaz , Ambareen Siraj , Denis Ulybyshev

Domain generation algorithms (DGAs) are frequently employed by malware to generate domains used for connecting to command-and-control (C2) servers. Recent work in DGA detection leveraged deep learning architectures like convolutional neural…

Cryptography and Security · Computer Science 2019-01-29 Joewie J. Koh , Barton Rhodes

Nowadays, malware campaigns have reached a high level of sophistication, thanks to the use of cryptography and covert communication channels over traditional protocols and services. In this regard, a typical approach to evade botnet…

Cryptography and Security · Computer Science 2021-01-25 Constantinos Patsakis , Fran Casino

Many malware families utilize domain generation algorithms (DGAs) to establish command and control (C&C) connections. While there are many methods to pseudorandomly generate domains, we focus in this paper on detecting (and generating)…

Cryptography and Security · Computer Science 2016-11-04 Hyrum S. Anderson , Jonathan Woodbridge , Bobby Filar

Malware applications typically use a command and control (C&C) server to manage bots to perform malicious activities. Domain Generation Algorithms (DGAs) are popular methods for generating pseudo-random domain names that can be used to…

Cryptography and Security · Computer Science 2020-03-13 Raaghavi Sivaguru , Jonathan Peck , Femi Olumofin , Anderson Nascimento , Martine De Cock

Modern malware typically makes use of a domain generation algorithm (DGA) to avoid command and control domains or IPs being seized or sinkholed. This means that an infected system may attempt to access many domains in an attempt to contact…

Cryptography and Security · Computer Science 2019-06-24 Ryan R. Curtin , Andrew B. Gardner , Slawomir Grzonkowski , Alexey Kleymenov , Alejandro Mosquera

Domain generation algorithm (DGA) is used by botnets to build a stealthy command and control (C&C) communication channel between the C&C server and the bots. A DGA can periodically produce a large number of pseudo-random algorithmically…

Cryptography and Security · Computer Science 2022-08-09 Zheng Wang

New malware emerges at a rapid pace and often incorporates Domain Generation Algorithms (DGAs) to avoid blocking the malware's connection to the command and control (C2) server. Current state-of-the-art classifiers are able to separate…

Cryptography and Security · Computer Science 2022-05-31 Arthur Drichel , Justus von Brandt , Ulrike Meyer

Domain generation algorithms (DGAs) are commonly leveraged by malware to create lists of domain names which can be used for command and control (C&C) purposes. Approaches based on machine learning have recently been developed to…

Generative AI and large language models (LLMs) have shown strong capabilities in code understanding, but their use in cybersecurity, particularly for malware detection and analysis, remains limited. Existing detection systems often fail to…

Information Retrieval · Computer Science 2025-10-23 Hamed Jelodar , Mohammad Meymani , Roozbeh Razavi-Far , Ali A. Ghorbani

This paper proposes a generic classification system designed to detect security threats based on the behavior of malware samples. The system relies on statistical features computed from proxy log fields to train detectors using a database…

Machine Learning · Statistics 2017-02-09 Lukas Machlica , Karel Bartos , Michal Sofka

DGA-based botnet, which uses Domain Generation Algorithms (DGAs) to evade supervision, has become a part of the most destructive threats to network security. Over the past decades, a wealth of defense mechanisms focusing on domain features…

Cryptography and Security · Computer Science 2020-09-22 Xin Fang , Xiaoqing Sun , Jiahai Yang , Xinran Liu

The parallel evolution of Large Language Models (LLMs) with advanced code-understanding capabilities and the increasing sophistication of malware presents a new frontier for cybersecurity research. This paper evaluates the efficacy of…

Cryptography and Security · Computer Science 2026-01-15 Aniesh Chawla , Udbhav Prasad

Domain generation algorithms (DGAs) prevent the connection between a botnet and its master from being blocked by generating a large number of domain names. Promising single-data-source approaches have been proposed for separating benign…

Cryptography and Security · Computer Science 2021-09-27 Arthur Drichel , Benedikt Holmes , Justus von Brandt , Ulrike Meyer

Large Language Models (LLMs) have revolutionised natural language processing tasks, particularly as chat agents. However, their applicability to threat detection problems remains unclear. This paper examines the feasibility of employing…

Cryptography and Security · Computer Science 2025-04-21 Paul R. B. Houssel , Priyanka Singh , Siamak Layeghy , Marius Portmann

Large language models (LLMs) are now routinely used to autonomously execute complex tasks, from natural language processing to dynamic workflows like web searches. The usage of tool-calling and Retrieval Augmented Generation (RAG) allows…

Cryptography and Security · Computer Science 2026-04-13 Dennis Rall , Bernhard Bauer , Mohit Mittal , Thomas Fraunholz
‹ Prev 1 2 3 10 Next ›