2021/01/02 by Ibrahim Yilmaz, Yilmaz, Ibrahim, Ambareen Siraj +3
Computer Science · #Advanced Malware Detection Techniques #Adversarial Robustness in Machine Learning #Artificial Intelligence (cs.AI) #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Network Security and Intrusion Detection
paper · pdf · doi:10.48550/arxiv.2101.00521
openalex publication_date 2021/01/02 · openalex created_date 2022/07/25 · openalex updated_date 2026/07/28
Domain Generation Algorithms (DGAs) are used by adversaries to establish\nCommand and Control (C &C) server communications during cyber attacks.\nBlacklists of known/identified C &C domains are often used as one of the\ndefense mechanisms. However, since blacklists are static and generated by\nsignature-based approaches, they can neither keep up nor detect\nnever-seen-before malicious domain names. Due to this shortcoming of blacklist\ndomain checking, machine learning algorithms have been used to address the\nproblem to some extent. However, when training is performed with limited\ndatasets, the algorithms are likely to fail in detecting new DGA variants. To\nmitigate this weakness, we successfully applied a DGA-based malicious domain\nclassifier using the Long Short-Term Memory (LSTM) method with a novel feature\nengineering technique. Our model's performance shows a higher level of accuracy\ncompared to a previously reported model from prior research. Additionally, we\npropose a new method using adversarial machine learning to generate\nnever-before-seen malware-related domain families that can be used to\nillustrate the shortcomings of machine learning algorithms in this regard.\nNext, we augment the training dataset with new samples such that it makes\ntraining of the machine learning models more effective in detecting\nnever-before-seen malicious domain name variants. Finally, to protect\nblacklists of malicious domain names from disclosure and tampering, we devise\nsecure data containers that store blacklists and guarantee their protection\nagainst adversarial access and modifications.\n