Domain generation algorithms detection with feature extraction and Domain Center construction.
Network attacks using Command and Control (C&C) servers have increased significantly. To hide their C&C servers, attackers often use Domain Generation Algorithms (DGA), which automatically generate domain names for C&C servers. Researchers have constructed many unique feature sets and de...
Main Authors: | , |
---|---|
Format: | Article |
Language: | English |
Published: |
Public Library of Science (PLoS)
2023-01-01
|
Series: | PLoS ONE |
Online Access: | https://doi.org/10.1371/journal.pone.0279866 |
_version_ | 1827986454862626816 |
---|---|
author | Xinjie Sun Zhifang Liu |
author_facet | Xinjie Sun Zhifang Liu |
author_sort | Xinjie Sun |
collection | DOAJ |
description | Network attacks using Command and Control (C&C) servers have increased significantly. To hide their C&C servers, attackers often use Domain Generation Algorithms (DGA), which automatically generate domain names for C&C servers. Researchers have constructed many unique feature sets and detected DGA domains through machine learning or deep learning models. However, due to the limited features contained in the domain name, the DGA detection results are limited. In order to overcome this problem, the domain name features, the Whois features and the N-gram features are extracted for DGA detection. To obtain the N-gram features, the domain name whitelist and blacklist substring feature sets are constructed. In addition, a deep learning model based on BiLSTM, Attention and CNN is constructed. Additionally, the Domain Center is constructed for fast classification of domain names. Multiple comparative experiment results prove that the proposed model not only gets the best Accuracy, Precision, Recall and F1, but also greatly reduces the detection time. |
first_indexed | 2024-04-09T23:30:32Z |
format | Article |
id | doaj.art-3b81fd1f8e04403e9f8f3c4cb183846b |
institution | Directory Open Access Journal |
issn | 1932-6203 |
language | English |
last_indexed | 2024-04-09T23:30:32Z |
publishDate | 2023-01-01 |
publisher | Public Library of Science (PLoS) |
record_format | Article |
series | PLoS ONE |
spelling | doaj.art-3b81fd1f8e04403e9f8f3c4cb183846b2023-03-21T05:31:33ZengPublic Library of Science (PLoS)PLoS ONE1932-62032023-01-01181e027986610.1371/journal.pone.0279866Domain generation algorithms detection with feature extraction and Domain Center construction.Xinjie SunZhifang LiuNetwork attacks using Command and Control (C&C) servers have increased significantly. To hide their C&C servers, attackers often use Domain Generation Algorithms (DGA), which automatically generate domain names for C&C servers. Researchers have constructed many unique feature sets and detected DGA domains through machine learning or deep learning models. However, due to the limited features contained in the domain name, the DGA detection results are limited. In order to overcome this problem, the domain name features, the Whois features and the N-gram features are extracted for DGA detection. To obtain the N-gram features, the domain name whitelist and blacklist substring feature sets are constructed. In addition, a deep learning model based on BiLSTM, Attention and CNN is constructed. Additionally, the Domain Center is constructed for fast classification of domain names. Multiple comparative experiment results prove that the proposed model not only gets the best Accuracy, Precision, Recall and F1, but also greatly reduces the detection time.https://doi.org/10.1371/journal.pone.0279866 |
spellingShingle | Xinjie Sun Zhifang Liu Domain generation algorithms detection with feature extraction and Domain Center construction. PLoS ONE |
title | Domain generation algorithms detection with feature extraction and Domain Center construction. |
title_full | Domain generation algorithms detection with feature extraction and Domain Center construction. |
title_fullStr | Domain generation algorithms detection with feature extraction and Domain Center construction. |
title_full_unstemmed | Domain generation algorithms detection with feature extraction and Domain Center construction. |
title_short | Domain generation algorithms detection with feature extraction and Domain Center construction. |
title_sort | domain generation algorithms detection with feature extraction and domain center construction |
url | https://doi.org/10.1371/journal.pone.0279866 |
work_keys_str_mv | AT xinjiesun domaingenerationalgorithmsdetectionwithfeatureextractionanddomaincenterconstruction AT zhifangliu domaingenerationalgorithmsdetectionwithfeatureextractionanddomaincenterconstruction |