Matches in SemOpenAlex for { <https://semopenalex.org/work/W3131488785> ?p ?o ?g. }
- W3131488785 abstract "Abstract Botnets and malware continue to avoid detection by static rule engines when using domain generation algorithms (DGAs) for callouts to unique, dynamically generated web addresses. Common DGA detection techniques fail to reliably detect DGA variants that combine random dictionary words to create domain names that closely mirror legitimate domains. To combat this, we created a novel hybrid neural network, Bilbo the “bagging” model, that analyses domains and scores the likelihood they are generated by such algorithms and therefore are potentially malicious. Bilbo is the first parallel usage of a convolutional neural network (CNN) and a long short-term memory (LSTM) network for DGA detection. Our unique architecture is found to be the most consistent in performance in terms of AUC, $$F_1$$ <mml:math xmlns:mml=http://www.w3.org/1998/Math/MathML><mml:msub><mml:mi>F</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:math> score, and accuracy when generalising across different dictionary DGA classification tasks compared to current state-of-the-art deep learning architectures. We validate using reverse-engineered dictionary DGA domains and detail our real-time implementation strategy for scoring real-world network logs within a large enterprise. In 4 h of actual network traffic, the model discovered at least five potential command-and-control networks that commercial vendor tools did not flag." @default.
- W3131488785 created "2021-03-01" @default.
- W3131488785 creator A5008596585 @default.
- W3131488785 creator A5027282036 @default.
- W3131488785 creator A5075250228 @default.
- W3131488785 creator A5080848978 @default.
- W3131488785 date "2021-02-22" @default.
- W3131488785 modified "2023-10-15" @default.
- W3131488785 title "Real-Time Detection of Dictionary DGA Network Traffic Using Deep Learning" @default.
- W3131488785 cites W17316494 @default.
- W3131488785 cites W1832693441 @default.
- W3131488785 cites W1919179112 @default.
- W3131488785 cites W1981294881 @default.
- W3131488785 cites W1989401787 @default.
- W3131488785 cites W1989957782 @default.
- W3131488785 cites W2074021442 @default.
- W3131488785 cites W2136495567 @default.
- W3131488785 cites W2470894770 @default.
- W3131488785 cites W2510523362 @default.
- W3131488785 cites W2528572867 @default.
- W3131488785 cites W2734389934 @default.
- W3131488785 cites W2762467223 @default.
- W3131488785 cites W2768793959 @default.
- W3131488785 cites W2772269457 @default.
- W3131488785 cites W2773270814 @default.
- W3131488785 cites W2773671123 @default.
- W3131488785 cites W2786906486 @default.
- W3131488785 cites W2792815878 @default.
- W3131488785 cites W2886922730 @default.
- W3131488785 cites W2890022913 @default.
- W3131488785 cites W2890928763 @default.
- W3131488785 cites W2900892325 @default.
- W3131488785 cites W2929803724 @default.
- W3131488785 cites W2951559648 @default.
- W3131488785 cites W2953040712 @default.
- W3131488785 cites W2963921497 @default.
- W3131488785 cites W2967189403 @default.
- W3131488785 cites W2968390691 @default.
- W3131488785 doi "https://doi.org/10.1007/s42979-021-00507-w" @default.
- W3131488785 hasPublicationYear "2021" @default.
- W3131488785 type Work @default.
- W3131488785 sameAs 3131488785 @default.
- W3131488785 citedByCount "18" @default.
- W3131488785 countsByYear W31314887852021 @default.
- W3131488785 countsByYear W31314887852022 @default.
- W3131488785 countsByYear W31314887852023 @default.
- W3131488785 crossrefType "journal-article" @default.
- W3131488785 hasAuthorship W3131488785A5008596585 @default.
- W3131488785 hasAuthorship W3131488785A5027282036 @default.
- W3131488785 hasAuthorship W3131488785A5075250228 @default.
- W3131488785 hasAuthorship W3131488785A5080848978 @default.
- W3131488785 hasBestOaLocation W31314887851 @default.
- W3131488785 hasConcept C108583219 @default.
- W3131488785 hasConcept C110875604 @default.
- W3131488785 hasConcept C111919701 @default.
- W3131488785 hasConcept C119857082 @default.
- W3131488785 hasConcept C134306372 @default.
- W3131488785 hasConcept C154945302 @default.
- W3131488785 hasConcept C22735295 @default.
- W3131488785 hasConcept C2988987868 @default.
- W3131488785 hasConcept C33923547 @default.
- W3131488785 hasConcept C36503486 @default.
- W3131488785 hasConcept C41008148 @default.
- W3131488785 hasConcept C50644808 @default.
- W3131488785 hasConcept C541664917 @default.
- W3131488785 hasConcept C81363708 @default.
- W3131488785 hasConceptScore W3131488785C108583219 @default.
- W3131488785 hasConceptScore W3131488785C110875604 @default.
- W3131488785 hasConceptScore W3131488785C111919701 @default.
- W3131488785 hasConceptScore W3131488785C119857082 @default.
- W3131488785 hasConceptScore W3131488785C134306372 @default.
- W3131488785 hasConceptScore W3131488785C154945302 @default.
- W3131488785 hasConceptScore W3131488785C22735295 @default.
- W3131488785 hasConceptScore W3131488785C2988987868 @default.
- W3131488785 hasConceptScore W3131488785C33923547 @default.
- W3131488785 hasConceptScore W3131488785C36503486 @default.
- W3131488785 hasConceptScore W3131488785C41008148 @default.
- W3131488785 hasConceptScore W3131488785C50644808 @default.
- W3131488785 hasConceptScore W3131488785C541664917 @default.
- W3131488785 hasConceptScore W3131488785C81363708 @default.
- W3131488785 hasIssue "2" @default.
- W3131488785 hasLocation W31314887851 @default.
- W3131488785 hasLocation W31314887852 @default.
- W3131488785 hasLocation W31314887853 @default.
- W3131488785 hasLocation W31314887854 @default.
- W3131488785 hasOpenAccess W3131488785 @default.
- W3131488785 hasPrimaryLocation W31314887851 @default.
- W3131488785 hasRelatedWork W2337926734 @default.
- W3131488785 hasRelatedWork W2795033129 @default.
- W3131488785 hasRelatedWork W2934080905 @default.
- W3131488785 hasRelatedWork W2942650110 @default.
- W3131488785 hasRelatedWork W2968586400 @default.
- W3131488785 hasRelatedWork W2974446506 @default.
- W3131488785 hasRelatedWork W4224267071 @default.
- W3131488785 hasRelatedWork W4311257506 @default.
- W3131488785 hasRelatedWork W4313563103 @default.
- W3131488785 hasRelatedWork W4316087074 @default.
- W3131488785 hasVolume "2" @default.
- W3131488785 isParatext "false" @default.
- W3131488785 isRetracted "false" @default.