Attackers typically influence communication using a command and control (C2) server. Threat actors frequently use domain generation algorithms (DGAs) to carry out attacks because they can generate a range of network locations that malware can use to connect with C2. Blacklisting and other conventional malware management techniques are not enough to combat DGA threats. In this research, we provide a machine learning approach for identifying and recognizing DGA domains in order to lessen the threat. We collect real-time threat data over a year from real-world traffic; we use the information; we find about the algorithms generating those DGA domains by applying the clustering method; and then we use this knowledge to classify DGA domains differently from regular domains. In this project, various machine learning classifier algorithms are studied through training on a dataset comprising hundreds of DGA and normal domains. Selected features that add to the overall polarity of the input are used as the basis for training. Performance is evaluated by computing precision, accuracy, etc. The best-performing approach is then determined by comparing these readings. These classifiers’ accuracy in identifying the polarity or emotions contained in a text is evaluated and computed using performance assessment metrics.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

An Assessment of the Development of DGA-Based Malware Detection Performance by Employing Machine Learning Techniques

  • X. S. Asha Shiny,
  • Amarajyothi Aramanda,
  • S. V. Suji Aparna,
  • K. Madhu,
  • M. Kamala,
  • M. Umamaheswara Rao

摘要

Attackers typically influence communication using a command and control (C2) server. Threat actors frequently use domain generation algorithms (DGAs) to carry out attacks because they can generate a range of network locations that malware can use to connect with C2. Blacklisting and other conventional malware management techniques are not enough to combat DGA threats. In this research, we provide a machine learning approach for identifying and recognizing DGA domains in order to lessen the threat. We collect real-time threat data over a year from real-world traffic; we use the information; we find about the algorithms generating those DGA domains by applying the clustering method; and then we use this knowledge to classify DGA domains differently from regular domains. In this project, various machine learning classifier algorithms are studied through training on a dataset comprising hundreds of DGA and normal domains. Selected features that add to the overall polarity of the input are used as the basis for training. Performance is evaluated by computing precision, accuracy, etc. The best-performing approach is then determined by comparing these readings. These classifiers’ accuracy in identifying the polarity or emotions contained in a text is evaluated and computed using performance assessment metrics.