详细信息

Detecting Domain Generation Algorithms Based on Reinforcement Learning  ( CPCI-S收录)  

文献类型:会议论文

英文题名:Detecting Domain Generation Algorithms Based on Reinforcement Learning

作者:Cheng Hua[1];Fang Yiquan[1];Chen Lihuang[1];Cai Jing[1]

机构:[1]East China Univ Sci & Technol, Sch Informat Sci & Engn, Shanghai, Peoples R China

会议论文集:International Conference on Cyber-Enabled Distributed Computing and Knowledge Discovery (CyberC)

会议日期:OCT 17-19, 2019

会议地点:Guilin Univ Elect Technol, Guilin, PEOPLES R CHINA

主办单位:Guilin Univ Elect Technol

语种:英文

外文关键词:DGA; domain name detection; reinforcement learning; LSTM

摘要:Ransomwares spread rapidly over the past two years, which poses great security threats to users. DGA domain name detection is one of the key technologies in detecting ransomwares. Existing detection methods are usually based on machine learning, which needs large amounts of training data. However, it is difficult to collect enough training samples for a specific DGA family in a short time, and few training samples would lead to overfitting of the detection model. A LSTM DGA generation model can obtain a lot of new data learned from few real DGA samples. Reinforcement Learning guides this LSTM generation model to be improved by evaluating its generated domain name, which is proposed as RL-LSTM DGA generation model. In experiments, a DGA domain name detection model (ATT-GRU model) trained by the generated DGAs, is used to compute accuracies of real DGAs (as test dataset) to assess the validity of generated domain names. Experiments show that the distribution of generated DGAs is sufficiently close to real DGAs, and can play an alternative role of real DGAs in detection model training.

参考文献:

正在载入数据...

版权所有©华东理工大学 重庆维普资讯有限公司 渝B2-20050021-7 
渝公网安备 50019002500408号 违法和不良信息举报中心