Explaining Machine Learning DGA Detectors from DNS Traffic Data

08/10/2022
by   Giorgio Piras, et al.
5

One of the most common causes of lack of continuity of online systems stems from a widely popular Cyber Attack known as Distributed Denial of Service (DDoS), in which a network of infected devices (botnet) gets exploited to flood the computational capacity of services through the commands of an attacker. This attack is made by leveraging the Domain Name System (DNS) technology through Domain Generation Algorithms (DGAs), a stealthy connection strategy that yet leaves suspicious data patterns. To detect such threats, advances in their analysis have been made. For the majority, they found Machine Learning (ML) as a solution, which can be highly effective in analyzing and classifying massive amounts of data. Although strongly performing, ML models have a certain degree of obscurity in their decision-making process. To cope with this problem, a branch of ML known as Explainable ML tries to break down the black-box nature of classifiers and make them interpretable and human-readable. This work addresses the problem of Explainable ML in the context of botnet and DGA detection, which at the best of our knowledge, is the first to concretely break down the decisions of ML classifiers when devised for botnet/DGA detection, therefore providing global and local explanations.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
12/18/2021

Does Explainable Machine Learning Uncover the Black Box in Vision Applications?

Machine learning (ML) in general and deep learning (DL) in particular ha...
research
04/28/2022

An Explainable Regression Framework for Predicting Remaining Useful Life of Machines

Prediction of a machine's Remaining Useful Life (RUL) is one of the key ...
research
06/08/2019

Guidelines for Responsible and Human-Centered Use of Explainable Machine Learning

Explainable machine learning (ML) has been implemented in numerous open ...
research
03/22/2021

Hardware Acceleration of Explainable Machine Learning using Tensor Processing Units

Machine learning (ML) is successful in achieving human-level performance...
research
08/19/2023

Causal Intersectionality and Dual Form of Gradient Descent for Multimodal Analysis: a Case Study on Hateful Memes

In the wake of the explosive growth of machine learning (ML) usage, part...
research
05/07/2020

Visualisation and knowledge discovery from interpretable models

Increasing number of sectors which affect human lives, are using Machine...
research
04/27/2021

Proceedings - AI/ML for Cybersecurity: Challenges, Solutions, and Novel Ideas at SIAM Data Mining 2021

Malicious cyber activity is ubiquitous and its harmful effects have dram...

Please sign up or login with your details

Forgot password? Click here to reset