Domain generation algorithms detection with feature extraction and Domain Center construction.

Network attacks using Command and Control (C&C) servers have increased significantly. To hide their C&C servers, attackers often use Domain Generation Algorithms (DGA), which automatically generate domain names for C&C servers. Researchers have constructed many unique feature sets and de...

Full description

Bibliographic Details
Main Authors: Xinjie Sun, Zhifang Liu
Format: Article
Language:English
Published: Public Library of Science (PLoS) 2023-01-01
Series:PLoS ONE
Online Access:https://doi.org/10.1371/journal.pone.0279866
_version_ 1827986454862626816
author Xinjie Sun
Zhifang Liu
author_facet Xinjie Sun
Zhifang Liu
author_sort Xinjie Sun
collection DOAJ
description Network attacks using Command and Control (C&C) servers have increased significantly. To hide their C&C servers, attackers often use Domain Generation Algorithms (DGA), which automatically generate domain names for C&C servers. Researchers have constructed many unique feature sets and detected DGA domains through machine learning or deep learning models. However, due to the limited features contained in the domain name, the DGA detection results are limited. In order to overcome this problem, the domain name features, the Whois features and the N-gram features are extracted for DGA detection. To obtain the N-gram features, the domain name whitelist and blacklist substring feature sets are constructed. In addition, a deep learning model based on BiLSTM, Attention and CNN is constructed. Additionally, the Domain Center is constructed for fast classification of domain names. Multiple comparative experiment results prove that the proposed model not only gets the best Accuracy, Precision, Recall and F1, but also greatly reduces the detection time.
first_indexed 2024-04-09T23:30:32Z
format Article
id doaj.art-3b81fd1f8e04403e9f8f3c4cb183846b
institution Directory Open Access Journal
issn 1932-6203
language English
last_indexed 2024-04-09T23:30:32Z
publishDate 2023-01-01
publisher Public Library of Science (PLoS)
record_format Article
series PLoS ONE
spelling doaj.art-3b81fd1f8e04403e9f8f3c4cb183846b2023-03-21T05:31:33ZengPublic Library of Science (PLoS)PLoS ONE1932-62032023-01-01181e027986610.1371/journal.pone.0279866Domain generation algorithms detection with feature extraction and Domain Center construction.Xinjie SunZhifang LiuNetwork attacks using Command and Control (C&C) servers have increased significantly. To hide their C&C servers, attackers often use Domain Generation Algorithms (DGA), which automatically generate domain names for C&C servers. Researchers have constructed many unique feature sets and detected DGA domains through machine learning or deep learning models. However, due to the limited features contained in the domain name, the DGA detection results are limited. In order to overcome this problem, the domain name features, the Whois features and the N-gram features are extracted for DGA detection. To obtain the N-gram features, the domain name whitelist and blacklist substring feature sets are constructed. In addition, a deep learning model based on BiLSTM, Attention and CNN is constructed. Additionally, the Domain Center is constructed for fast classification of domain names. Multiple comparative experiment results prove that the proposed model not only gets the best Accuracy, Precision, Recall and F1, but also greatly reduces the detection time.https://doi.org/10.1371/journal.pone.0279866
spellingShingle Xinjie Sun
Zhifang Liu
Domain generation algorithms detection with feature extraction and Domain Center construction.
PLoS ONE
title Domain generation algorithms detection with feature extraction and Domain Center construction.
title_full Domain generation algorithms detection with feature extraction and Domain Center construction.
title_fullStr Domain generation algorithms detection with feature extraction and Domain Center construction.
title_full_unstemmed Domain generation algorithms detection with feature extraction and Domain Center construction.
title_short Domain generation algorithms detection with feature extraction and Domain Center construction.
title_sort domain generation algorithms detection with feature extraction and domain center construction
url https://doi.org/10.1371/journal.pone.0279866
work_keys_str_mv AT xinjiesun domaingenerationalgorithmsdetectionwithfeatureextractionanddomaincenterconstruction
AT zhifangliu domaingenerationalgorithmsdetectionwithfeatureextractionanddomaincenterconstruction