Invention Grant
- Patent Title: Identifying malware communications with DGA generated domains by discriminative learning
-
Application No.: US14806236Application Date: 2015-07-22
-
Publication No.: US09781139B2Publication Date: 2017-10-03
- Inventor: Michal Sofka , Lukas Machlica , Karel Bartos , David McGrew
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Edell, Shapiro & Finnan, LLC
- Main IPC: G06F11/00
- IPC: G06F11/00 ; G06F12/14 ; G06F12/16 ; G08B23/00 ; H04L29/06 ; G06N99/00 ; H04L29/12

Abstract:
Techniques are presented to identify malware communication with domain generation algorithm (DGA) generated domains. Sample domain names are obtained and labeled as DGA domains, non-DGA domains or suspicious domains. A classifier is trained in a first stage based on the sample domain names. Sample proxy logs including proxy logs of DGA domains and proxy logs of non-DGA domains are obtained to train the classifier in a second stage based on the plurality of sample domain names and the plurality of sample proxy logs. Live traffic proxy logs are obtained and the classifier is tested by classifying the live traffic proxy logs as DGA proxy logs, and the classifier is forwarded to a second computing device to identify network communication of a third computing device as malware network communication with DGA domains via a network interface unit of the third computing device based on the trained and tested classifier.
Public/Granted literature
- US20170026390A1 Identifying Malware Communications with DGA Generated Domains by Discriminative Learning Public/Granted day:2017-01-26
Information query