中文
相关论文

相关论文: Improving DGA-Based Malicious Domain Classifiers f…

200 篇论文

Various families of malware use domain generation algorithms (DGAs) to generate a large number of pseudo-random domain names to connect to a command and control (C&C) server. In order to block DGA C&C traffic, security organizations must…

密码学与安全 · 计算机科学 2016-11-04 Jonathan Woodbridge , Hyrum S. Anderson , Anjum Ahuja , Daniel Grant

Malware applications typically use a command and control (C&C) server to manage bots to perform malicious activities. Domain Generation Algorithms (DGAs) are popular methods for generating pseudo-random domain names that can be used to…

密码学与安全 · 计算机科学 2020-03-13 Raaghavi Sivaguru , Jonathan Peck , Femi Olumofin , Anderson Nascimento , Martine De Cock

Many malware families utilize domain generation algorithms (DGAs) to establish command and control (C&C) connections. While there are many methods to pseudorandomly generate domains, we focus in this paper on detecting (and generating)…

密码学与安全 · 计算机科学 2016-11-04 Hyrum S. Anderson , Jonathan Woodbridge , Bobby Filar

Domain generation algorithms (DGAs) are commonly leveraged by malware to create lists of domain names which can be used for command and control (C&C) purposes. Approaches based on machine learning have recently been developed to…

Modern malware families often rely on domain-generation algorithms (DGAs) to determine rendezvous points to their command-and-control server. Traditional defence strategies (such as blacklisting domains or IP addresses) are inadequate…

密码学与安全 · 计算机科学 2017-09-22 Pierre Lison , Vasileios Mavroeidis

Domain Generation Algorithms (DGAs) are frequently used to generate numerous domains for use by botnets. These domains are often utilized as rendezvous points for servers that malware has command and control over. There are many algorithms…

机器学习 · 计算机科学 2020-02-18 Isaac Corley , Jonathan Lwowski , Justin Hoffman

Domain Generation Algorithms (DGAs) are malicious techniques used by malware to dynamically generate seemingly random domain names for communication with Command & Control (C&C) servers. Due to the fast and simple generation of DGA domains,…

密码学与安全 · 计算机科学 2024-11-08 Md Abu Sayed , Asif Rahman , Christopher Kiekintveld , Sebastian Garcia

The sophistication of modern malware, specifically regarding communication with Command and Control (C2) servers, has rendered static blacklist-based defenses obsolete. The use of Domain Generation Algorithms (DGA) allows attackers to…

机器学习 · 计算机科学 2025-12-10 Maria Milena Araujo Felix

Nowadays, malware campaigns have reached a high level of sophistication, thanks to the use of cryptography and covert communication channels over traditional protocols and services. In this regard, a typical approach to evade botnet…

密码学与安全 · 计算机科学 2021-01-25 Constantinos Patsakis , Fran Casino

Domain generation algorithms (DGAs) are frequently employed by malware to generate domains used for connecting to command-and-control (C2) servers. Recent work in DGA detection leveraged deep learning architectures like convolutional neural…

密码学与安全 · 计算机科学 2019-01-29 Joewie J. Koh , Barton Rhodes

Domain generation algorithms (DGAs) are commonly used by botnets to generate domain names through which bots can establish a resilient communication channel with their command and control servers. Recent publications presented deep…

密码学与安全 · 计算机科学 2019-02-26 Lior Sidi , Asaf Nadler , Asaf Shabtai

Modern malware typically makes use of a domain generation algorithm (DGA) to avoid command and control domains or IPs being seized or sinkholed. This means that an infected system may attempt to access many domains in an attempt to contact…

密码学与安全 · 计算机科学 2019-06-24 Ryan R. Curtin , Andrew B. Gardner , Slawomir Grzonkowski , Alexey Kleymenov , Alejandro Mosquera

New malware emerges at a rapid pace and often incorporates Domain Generation Algorithms (DGAs) to avoid blocking the malware's connection to the command and control (C2) server. Current state-of-the-art classifiers are able to separate…

密码学与安全 · 计算机科学 2022-05-31 Arthur Drichel , Justus von Brandt , Ulrike Meyer

One of the most common causes of lack of continuity of online systems stems from a widely popular Cyber Attack known as Distributed Denial of Service (DDoS), in which a network of infected devices (botnet) gets exploited to flood the…

密码学与安全 · 计算机科学 2022-08-11 Giorgio Piras , Maura Pintor , Luca Demetrio , Battista Biggio

Numerous malware families rely on domain generation algorithms (DGAs) to establish a connection to their command and control (C2) server. Counteracting DGAs, several machine learning classifiers have been proposed enabling the…

密码学与安全 · 计算机科学 2021-06-24 Arthur Drichel , Nils Faerber , Ulrike Meyer

Domain generation algorithm (DGA) is used by botnets to build a stealthy command and control (C&C) communication channel between the C&C server and the bots. A DGA can periodically produce a large number of pseudo-random algorithmically…

密码学与安全 · 计算机科学 2022-08-09 Zheng Wang

An important aspect of many botnets is their capability to generate pseudorandom domain names using Domain Generation Algorithms (DGAs). A cyber criminal can register such domains to establish periodically changing rendezvous points with…

密码学与安全 · 计算机科学 2023-01-13 Nils Weissgerber , Thorsten Jenke , Elmar Padilla , Lilli Bruckschen

Domain generation algorithms (DGAs) prevent the connection between a botnet and its master from being blocked by generating a large number of domain names. Promising single-data-source approaches have been proposed for separating benign…

密码学与安全 · 计算机科学 2021-09-27 Arthur Drichel , Benedikt Holmes , Justus von Brandt , Ulrike Meyer

In this work, we conduct a comprehensive study on the robustness of domain generation algorithm (DGA) classifiers. We implement 32 white-box attacks, 19 of which are very effective and induce a false-negative rate (FNR) of $\approx$ 100\%…

密码学与安全 · 计算机科学 2024-04-10 Arthur Drichel , Marc Meyer , Ulrike Meyer

This paper proposes a generic classification system designed to detect security threats based on the behavior of malware samples. The system relies on statistical features computed from proxy log fields to train detectors using a database…

机器学习 · 统计学 2017-02-09 Lukas Machlica , Karel Bartos , Michal Sofka
‹ 上一页 1 2 3 10 下一页 ›