Back to Search Start Over

DGA domain detection and botnet prevention using Q-learning for POMDP

Authors :
Y. V. Bubnov
N. N. Ivanov
Source :
Doklady Belorusskogo gosudarstvennogo universiteta informatiki i radioèlektroniki, Vol 19, Iss 2, Pp 91-99 (2021)
Publication Year :
2021
Publisher :
Educational institution «Belarusian State University of Informatics and Radioelectronics», 2021.

Abstract

An effective method for preventing the operation of computer network nodes for organizing a botnet is proposed. A botnet is a collection of devices connected via the Internet for the purpose of organizing DDoS attacks, stealing data, sending spam and other malicious actions. The described method implies the detection of generated domain names in DNS queries using a neural network with parallel organization of convolutional and bidirectional recurrent layers. The effectiveness of the method is based on the assumption that generated domain names are used to create a botnet for merging. Experiments confirm that the proposed neural network is superior to the accuracy of existing counterparts on the UMUDGA dataset. The estimation of the quality of recognition of generated domain names using ROC analysis is calculated for a trained neural network. The article also formulates a model for controlling detectors using a partially observable Markov decisionmaking process to block infected nodes of a computer network. The search for the optimal policy for the formulated model by means of Q-learning of value agents is proposed. A comparative analysis of the average, minimum and maximum value of actions taken by agents in the process of interacting with the environment is carried out.

Details

Language :
Russian
ISSN :
17297648
Volume :
19
Issue :
2
Database :
Directory of Open Access Journals
Journal :
Doklady Belorusskogo gosudarstvennogo universiteta informatiki i radioèlektroniki
Publication Type :
Academic Journal
Accession number :
edsdoj.1c6ea204f8134396a8b20048e7f5c46d
Document Type :
article
Full Text :
https://doi.org/10.35596/1729-7648-2021-19-2-91-99