Analyzing the Real-World Applicability of DGA Classifiers

06/19/2020
by   Arthur Drichel, et al.
0

Separating benign domains from domains generated by DGAs with the help of a binary classifier is a well-studied problem for which promising performance results have been published. The corresponding multiclass task of determining the exact DGA that generated a domain enabling targeted remediation measures is less well studied. Selecting the most promising classifier for these tasks in practice raises a number of questions that have not been addressed in prior work so far. These include the questions on which traffic to train in which network and when, just as well as how to assess robustness against adversarial attacks. Moreover, it is unclear which features lead a classifier to a decision and whether the classifiers are real-time capable. In this paper, we address these issues and thus contribute to bringing DGA detection classifiers closer to practical use. In this context, we propose one novel classifier based on residual neural networks for each of the two tasks and extensively evaluate them as well as previously proposed classifiers in a unified setting. We not only evaluate their classification performance but also compare them with respect to explainability, robustness, and training and classification speed. Finally, we show that our newly proposed binary classifier generalizes well to other networks, is time-robust, and able to identify previously unknown DGAs.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
06/23/2021

First Step Towards EXPLAINable DGA Multiclass Classification

Numerous malware families rely on domain generation algorithms (DGAs) to...
research
03/21/2022

On The Robustness of Offensive Language Classifiers

Social media platforms are deploying machine learning based offensive la...
research
03/12/2020

Inline Detection of DGA Domains Using Side Information

Malware applications typically use a command and control (C C) server ...
research
05/03/2019

CharBot: A Simple and Effective Method for Evading DGA Classifiers

Domain generation algorithms (DGAs) are commonly leveraged by malware to...
research
05/30/2022

Detecting Unknown DGAs without Context Information

New malware emerges at a rapid pace and often incorporates Domain Genera...
research
06/30/2019

Fooling a Real Car with Adversarial Traffic Signs

The attacks on the neural-network-based classifiers using adversarial im...
research
07/29/2023

Multi-output Headed Ensembles for Product Item Classification

In this paper, we revisit the problem of product item classification for...

Please sign up or login with your details

Forgot password? Click here to reset