AutoEncoded Domains with Mean Activation for DGA Botnet Detection

Binay Dahal, Yoohwan Kim · 2019

Botnets are the powerful and effective way of performing malicious activities over the internet. Over the years, it has evolved into many forms. Earlier bots used static IP to communicate with their command and control server. This method stopped working as soon as that specific IP was identified and blocked. These days, domain fluxing botnets are mostly in practice. The idea is, using Dynamically Generation Algorithm (DGA) to generate domains and use it to connect with C&C server. Numerous researches have been done to detect DGA botnets. These includes deriving features based on alphanumeric distribution of DGA domains and performing classification on it. Other studies include network logs analysis, time series analysis etc. Most of these domain classification works rely upon the features developed and may not work well if the botmaster decides to generate domain with completely new features. We are concerned with developing algorithm that is resilient to feature change that also work well for domain generated by completely new algorithm that was not seen before. We generated 16 bit representation of domains using autoencoder and classified it as benign or DGA generated using supervised learning(with neural net and SVM). To make it work with previously unseen algorithm, we tweaked our method with mean activation of 16-bit domain representation. This helped improve classification accuracy for completely new set of domain generation algorithm by up to 16%.

Read the paper · More papers on PaperTik