Detection of DGA-based Malware Communications from DoH Traffic Using Machine Learning Analysis

Detection of DGA-based Malware Communications from DoH Traffic Using Machine Learning Analysis
复制标题

DOI:
10.1109/ccnc51644.2023.10059835
复制
发表时间:
2023-01
期刊:
2023 IEEE 20th Consumer Communications & Networking Conference (CCNC)
影响因子:
--
通讯作者:
Rikima Mitsuhashi;Yong Jin;K. Iida;Takahiro Shinagawa;Y. Takai
Rikima Mitsuhashi;Yong Jin;K. Iida;Takahiro Shinagawa;Y. Takai
中科院分区:
其他
文献类型:
--
作者:
Rikima Mitsuhashi;Yong Jin;K. Iida;Takahiro Shinagawa;Y. Takai

文献摘要

被引文献

相似文献

加密域名解析可以降低互联网用户隐私泄露的风险,但也可能阻止网络管理员检测到可疑通信。由于近年来支持基于HTTPS的域名解析(DoH)的操作系统越来越多,使用域生成算法(DGA)的恶意软件可以利用它来隐藏生成的域名。本文提出了一个从DoH流量中检测基于DGA的恶意软件通信的系统。该系统基于分层机器学习分析的概念,使用梯度提升决策树(GBDT)和树集成模型对网络流量进行分类。评估证实,该系统能够以99.12%的准确率检测由PadCrypt、Sisron、Tinba和ZLoader生成的DoH流量。结果表明,该系统能够以足够的准确度从DoH流量中检测出不同的基于DGA的恶意软件通信,从而为网络管理员提供支持。
Encrypted domain name resolution can reduce the risk of privacy leakage for Internet users, but it may also prevent network administrators from detecting suspicious communications. Since operating systems supporting DNS over HTTPS (DoH) have increased in recent years, malware that uses Domain Generation Algorithm (DGA) can exploit it to hide the generated domain names. In this paper, we propose a system that detects DGA-based malware communications from DoH traffic. Based on the concept of hierarchical machine learning analysis, the proposed system classifies network traffic with Gradient Boosting Decision Tree (GBDT) and tree-ensemble models. The evaluation confirmed that the system was able to detect DoH traffic generated by PadCrypt, Sisron, Tinba, and Zloader with 99.12% accuracy. The results indicate that the system has the ability to detect different DGA-based malware communications from DoH traffic with sufficient accuracy to support network administrators.