Invention Grant
- Patent Title: System and method for detecting domain generation algorithms (DGAs) using deep learning and signal processing techniques
-
Application No.: US17552973Application Date: 2021-12-16
-
Publication No.: US11436499B2Publication Date: 2022-09-06
- Inventor: Lee Joon Sern , Gui Peng David Yam , Quek Han Yang , Chan Jin Hao
- Applicant: Ensign Infosecurity Pte. Ltd.
- Applicant Address: SG Singapore
- Assignee: Ensign Infosecurity Pte. Ltd.
- Current Assignee: Ensign Infosecurity Pte. Ltd.
- Current Assignee Address: SG Singapore
- Agency: Sterne, Kessler, Goldstein & Fox P.L.L.C.
- Priority: SG10202100813P 20210126
- Main IPC: G06N3/08
- IPC: G06N3/08 ; H04L61/4511 ; G06F17/14

Abstract:
System and method for detecting domain names that exhibit Domain Generation Algorithm (DGA) like behaviours from a stream of Domain Name System (DNS) records. In particular, this document describes a system comprising a deep learning classifier (DL-C) module for receiving and filtering the stream of DNS records before the filtered DNS records, which have been determined to possess domain names that exhibit DGA behaviour are provided to a series filter-classifier (SFC) module. The SFC module then groups the records into various series based on source IP, destination IP and time. For each series, it then filters away records that do not exhibit the dominant DGA characteristics of the series. Finally, for each series, it makes use of the remaining DNS records' timestamps to generate a time series of DGA occurrences and then, using this time series of occurrences, determine the number of DGA bursts throughout the time period of analysis.
Public/Granted literature
Information query