Themis: A Novel Detection Approach for Detecting Mixed Algorithmically Generated Domains

Chaoyi Zheng,Qian Qiang,Tianning Zang,Wenhan Chao,Yuan Zhou
DOI: https://doi.org/10.1109/msn48538.2019.00057
2019-01-01
Abstract:As DGA (Domain Generation Algorithm) detection technologies and systems become more and more complex, more types of AGD (Algorithmically Generated Domain) appear: Dictionary-based AGD, Hash-based AGD, etc. This paper applies deep learning to the field of network security, proposes a lightweight AGD detection approach, Themis, which can classify domain names into legitimate domain names or AGDs through domain name strings. Themis combines WordNet and GRU to capture the different characteristics of legitimate domain name and AGD for classification. Compared with the prior art, Themis has two differences: 1) Themis is the first approach to detect mixed AGD (Arithmetic-based and Dictionary-based); 2) Themis performs well in detecting unknowns AGD.
What problem does this paper attempt to address?