A Game-Based Adversarial DGA Detection Scheme Using Multi-Level Incremental Random Forest

IEEE TRANSACTIONS ON NETWORK SCIENCE AND ENGINEERING(2024)

引用 0|浏览6
暂无评分
摘要
Security vendors can take down botnets by detecting the malicious domain names crafted by attackers. However, the adversarial Domain Generation Algorithms (DGAs) greatly challenge the existing domain detection schemes, in particular, adversarial DGAs can actively compromise arbitrarily specified domain detection systems by crafting the adversarial domain names. To resist adversarial DGAs, we propose a game theory-based defending strategy, which launches adversarial DGA and trains an incremental domain detector alternately. While we find the game-based strategy cannot achieve the expected detection accuracy due to two problems: the failure of incremental training and the problem of the catastrophic forgetting. To this end, we propose a multi-level incremental random forest model, which settles the above problems by splitting the leaf nodes of the decision trees and increasing the levels of the original random forest. The experimental results on the real-life dataset demonstrate the proposed detection method significantly outperforms the competing schemes when detecting adversarial DGAs (improves the detection AUC by 42%) and presents comparable performance when defending against non-adversarial DGAs.
更多
查看译文
关键词
Detectors,Games,Training,Reliability,Chatbots,Servers,Radio frequency,Malicious domain name detection,incremental learning,adversarial domain generation algorithm
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要