{"id":"https://openalex.org/W3013287073","doi":"https://doi.org/10.1007/s42979-021-00507-w","title":"Real-Time Detection of Dictionary DGA Network Traffic Using Deep Learning","display_name":"Real-Time Detection of Dictionary DGA Network Traffic Using Deep Learning","publication_year":2021,"publication_date":"2021-02-22","ids":{"openalex":"https://openalex.org/W3013287073","doi":"https://doi.org/10.1007/s42979-021-00507-w","mag":"3013287073"},"language":"en","primary_location":{"id":"doi:10.1007/s42979-021-00507-w","is_oa":true,"landing_page_url":"https://doi.org/10.1007/s42979-021-00507-w","pdf_url":"https://link.springer.com/content/pdf/10.1007/s42979-021-00507-w.pdf","source":{"id":"https://openalex.org/S4210174798","display_name":"SN Computer Science","issn_l":"2661-8907","issn":["2661-8907","2662-995X"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319965","host_organization_name":"Springer Nature","host_organization_lineage":["https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Nature"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"SN Computer Science","raw_type":"journal-article"},"type":"preprint","indexed_in":["arxiv","crossref","datacite"],"open_access":{"is_oa":true,"oa_status":"hybrid","oa_url":"https://link.springer.com/content/pdf/10.1007/s42979-021-00507-w.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5027282036","display_name":"Kate Highnam","orcid":"https://orcid.org/0000-0003-4752-9334"},"institutions":[{"id":"https://openalex.org/I47508984","display_name":"Imperial College London","ror":"https://ror.org/041kmwe10","country_code":"GB","type":"education","lineage":["https://openalex.org/I47508984"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Kate Highnam","raw_affiliation_strings":["Imperial College London, London, UK","Imperial College London"],"raw_orcid":"https://orcid.org/0000-0003-4752-9334","affiliations":[{"raw_affiliation_string":"Imperial College London, London, UK","institution_ids":["https://openalex.org/I47508984"]},{"raw_affiliation_string":"Imperial College London","institution_ids":["https://openalex.org/I47508984"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5008596585","display_name":"Domenic Puzio","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Domenic Puzio","raw_affiliation_strings":["Kensho Technologies, McLean, VA, USA","Kensho Technologies, McLean, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Kensho Technologies, McLean, VA, USA","institution_ids":[]},{"raw_affiliation_string":"Kensho Technologies, McLean, USA","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101913842","display_name":"Song Luo","orcid":"https://orcid.org/0000-0003-1498-5253"},"institutions":[{"id":"https://openalex.org/I2250653659","display_name":"Tencent (China)","ror":"https://ror.org/00hhjss72","country_code":"CN","type":"company","lineage":["https://openalex.org/I2250653659"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Song Luo","raw_affiliation_strings":["Tencent, Shenzhen, China","Tencent, ShenZhen, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Tencent, Shenzhen, China","institution_ids":["https://openalex.org/I2250653659"]},{"raw_affiliation_string":"Tencent, ShenZhen, China","institution_ids":["https://openalex.org/I2250653659"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5036583884","display_name":"Nicholas R. Jennings","orcid":"https://orcid.org/0000-0003-0166-248X"},"institutions":[{"id":"https://openalex.org/I47508984","display_name":"Imperial College London","ror":"https://ror.org/041kmwe10","country_code":"GB","type":"education","lineage":["https://openalex.org/I47508984"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Nicholas R. Jennings","raw_affiliation_strings":["Imperial College London, London, UK","Imperial College London"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Imperial College London, London, UK","institution_ids":["https://openalex.org/I47508984"]},{"raw_affiliation_string":"Imperial College London","institution_ids":["https://openalex.org/I47508984"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":{"value":2290,"currency":"EUR","value_usd":2890},"apc_paid":{"value":2290,"currency":"EUR","value_usd":2890},"fwci":1.1223,"has_fulltext":true,"cited_by_count":7,"citation_normalized_percentile":{"value":0.78305446,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":98},"biblio":{"volume":"2","issue":"2","first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11644","display_name":"Spam and Phishing Detection","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7264803647994995},{"id":"https://openalex.org/keywords/botnet","display_name":"Botnet","score":0.7246417999267578},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.6647135615348816},{"id":"https://openalex.org/keywords/convolutional-neural-network","display_name":"Convolutional neural network","score":0.6129515171051025},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.6003036499023438},{"id":"https://openalex.org/keywords/domain","display_name":"Domain (mathematical analysis)","score":0.5986337065696716},{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.5787227749824524},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.5565186738967896},{"id":"https://openalex.org/keywords/vendor","display_name":"Vendor","score":0.4921843111515045},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.46998631954193115},{"id":"https://openalex.org/keywords/domain-name","display_name":"Domain name","score":0.46752476692199707},{"id":"https://openalex.org/keywords/state","display_name":"State (computer science)","score":0.41226625442504883},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.339949369430542},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.11330509185791016},{"id":"https://openalex.org/keywords/algorithm","display_name":"Algorithm","score":0.10145989060401917},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.09358164668083191},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.07260209321975708}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7264803647994995},{"id":"https://openalex.org/C22735295","wikidata":"https://www.wikidata.org/wiki/Q317671","display_name":"Botnet","level":3,"score":0.7246417999267578},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6647135615348816},{"id":"https://openalex.org/C81363708","wikidata":"https://www.wikidata.org/wiki/Q17084460","display_name":"Convolutional neural network","level":2,"score":0.6129515171051025},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.6003036499023438},{"id":"https://openalex.org/C36503486","wikidata":"https://www.wikidata.org/wiki/Q11235244","display_name":"Domain (mathematical analysis)","level":2,"score":0.5986337065696716},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.5787227749824524},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.5565186738967896},{"id":"https://openalex.org/C2777338717","wikidata":"https://www.wikidata.org/wiki/Q1762621","display_name":"Vendor","level":2,"score":0.4921843111515045},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.46998631954193115},{"id":"https://openalex.org/C2988987868","wikidata":"https://www.wikidata.org/wiki/Q32635","display_name":"Domain name","level":3,"score":0.46752476692199707},{"id":"https://openalex.org/C48103436","wikidata":"https://www.wikidata.org/wiki/Q599031","display_name":"State (computer science)","level":2,"score":0.41226625442504883},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.339949369430542},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.11330509185791016},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.10145989060401917},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.09358164668083191},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.07260209321975708},{"id":"https://openalex.org/C162853370","wikidata":"https://www.wikidata.org/wiki/Q39809","display_name":"Marketing","level":1,"score":0.0},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0},{"id":"https://openalex.org/C144133560","wikidata":"https://www.wikidata.org/wiki/Q4830453","display_name":"Business","level":0,"score":0.0}],"mesh":[],"locations_count":6,"locations":[{"id":"doi:10.1007/s42979-021-00507-w","is_oa":true,"landing_page_url":"https://doi.org/10.1007/s42979-021-00507-w","pdf_url":"https://link.springer.com/content/pdf/10.1007/s42979-021-00507-w.pdf","source":{"id":"https://openalex.org/S4210174798","display_name":"SN Computer Science","issn_l":"2661-8907","issn":["2661-8907","2662-995X"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319965","host_organization_name":"Springer Nature","host_organization_lineage":["https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Nature"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"SN Computer Science","raw_type":"journal-article"},{"id":"pmh:oai:arXiv.org:2003.12805","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2003.12805","pdf_url":"https://arxiv.org/pdf/2003.12805","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},{"id":"mag:3013287073","is_oa":true,"landing_page_url":"http://export.arxiv.org/pdf/2003.12805","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"arXiv (Cornell University)","raw_type":null},{"id":"pmh:oai:spiral.imperial.ac.uk:10044/1/77914","is_oa":false,"landing_page_url":"http://hdl.handle.net/10044/1/77914","pdf_url":null,"source":{"id":"https://openalex.org/S4306401396","display_name":"Spiral (Imperial College London)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I47508984","host_organization_name":"Imperial College London","host_organization_lineage":["https://openalex.org/I47508984"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"Working Paper"},{"id":"pmh:oai:spiral.imperial.ac.uk:10044/1/87710","is_oa":true,"landing_page_url":"http://hdl.handle.net/10044/1/87710","pdf_url":null,"source":{"id":"https://openalex.org/S4306401396","display_name":"Spiral (Imperial College London)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I47508984","host_organization_name":"Imperial College London","host_organization_lineage":["https://openalex.org/I47508984"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"110","raw_type":"Journal Article"},{"id":"doi:10.48550/arxiv.2003.12805","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2003.12805","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.1007/s42979-021-00507-w","is_oa":true,"landing_page_url":"https://doi.org/10.1007/s42979-021-00507-w","pdf_url":"https://link.springer.com/content/pdf/10.1007/s42979-021-00507-w.pdf","source":{"id":"https://openalex.org/S4210174798","display_name":"SN Computer Science","issn_l":"2661-8907","issn":["2661-8907","2662-995X"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319965","host_organization_name":"Springer Nature","host_organization_lineage":["https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Nature"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"SN Computer Science","raw_type":"journal-article"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/9","score":0.4099999964237213,"display_name":"Industry, innovation and infrastructure"}],"awards":[],"funders":[],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W3013287073.pdf","grobid_xml":"https://content.openalex.org/works/W3013287073.grobid-xml"},"referenced_works_count":41,"referenced_works":["https://openalex.org/W17316494","https://openalex.org/W1832693441","https://openalex.org/W1919179112","https://openalex.org/W1938755728","https://openalex.org/W1981294881","https://openalex.org/W1989401787","https://openalex.org/W1989957782","https://openalex.org/W2074021442","https://openalex.org/W2136495567","https://openalex.org/W2171313960","https://openalex.org/W2271840356","https://openalex.org/W2464432954","https://openalex.org/W2470894770","https://openalex.org/W2510523362","https://openalex.org/W2528572867","https://openalex.org/W2546910111","https://openalex.org/W2587019100","https://openalex.org/W2591856843","https://openalex.org/W2592440977","https://openalex.org/W2614419969","https://openalex.org/W2734389934","https://openalex.org/W2759618680","https://openalex.org/W2762467223","https://openalex.org/W2768793959","https://openalex.org/W2772269457","https://openalex.org/W2773270814","https://openalex.org/W2773671123","https://openalex.org/W2786906486","https://openalex.org/W2792815878","https://openalex.org/W2886922730","https://openalex.org/W2890022913","https://openalex.org/W2890928763","https://openalex.org/W2900892325","https://openalex.org/W2929803724","https://openalex.org/W2950338739","https://openalex.org/W2951559648","https://openalex.org/W2953040712","https://openalex.org/W2963921497","https://openalex.org/W2967189403","https://openalex.org/W2968390691","https://openalex.org/W2971890500"],"related_works":["https://openalex.org/W3179676507","https://openalex.org/W3094514336","https://openalex.org/W3046395559","https://openalex.org/W2907290714","https://openalex.org/W2997212066","https://openalex.org/W2773671123","https://openalex.org/W3086218180","https://openalex.org/W2938266968","https://openalex.org/W3197465574","https://openalex.org/W3126320415","https://openalex.org/W2968586400","https://openalex.org/W2546910111","https://openalex.org/W3012227398","https://openalex.org/W3195903966","https://openalex.org/W3178436634","https://openalex.org/W2898678921","https://openalex.org/W3198971113","https://openalex.org/W3016266335","https://openalex.org/W3044066880","https://openalex.org/W3134204681"],"abstract_inverted_index":{"Abstract":[0],"Botnets":[1],"and":[2,67,77,94,124,148],"malware":[3],"continue":[4],"to":[5,20,31,41,109,135],"avoid":[6],"detection":[7,28],"by":[8,74],"static":[9],"rule":[10],"engines":[11],"when":[12,126],"using":[13,143],"domain":[14,43],"generation":[15],"algorithms":[16,76],"(DGAs)":[17],"for":[18,101,154],"callouts":[19],"unique,":[21],"dynamically":[22],"generated":[23,73],"web":[24],"addresses.":[25],"Common":[26],"DGA":[27,34,102,131,146],"techniques":[29],"fail":[30],"reliably":[32],"detect":[33],"variants":[35],"that":[36,45,64,179],"combine":[37],"random":[38],"dictionary":[39,130,145],"words":[40],"create":[42],"names":[44],"closely":[46],"mirror":[47],"legitimate":[48],"domains.":[49],"To":[50],"combat":[51],"this,":[52],"we":[53],"created":[54],"a":[55,89,95,160],"novel":[56],"hybrid":[57],"neural":[58,91],"network,":[59],"Bilbo":[60,82],"the":[61,69,84,111,170],"\u201cbagging\u201d":[62],"model,":[63],"analyses":[65],"domains":[66,147],"scores":[68],"likelihood":[70],"they":[71],"are":[72,79],"such":[75],"therefore":[78],"potentially":[80],"malicious.":[81],"is":[83,107],"first":[85],"parallel":[86],"usage":[87],"of":[88,118,166],"convolutional":[90],"network":[92,100,157,168],"(CNN)":[93],"long":[96],"short-term":[97],"memory":[98],"(LSTM)":[99],"detection.":[103],"Our":[104],"unique":[105],"architecture":[106],"found":[108],"be":[110],"most":[112],"consistent":[113],"in":[114,116],"performance":[115],"terms":[117],"AUC,":[119],"$$F_1$$":[120],"<mml:math":[121],"xmlns:mml=\"http://www.w3.org/1998/Math/MathML\"><mml:msub><mml:mi>F</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:math>":[122],"score,":[123],"accuracy":[125],"generalising":[127],"across":[128],"different":[129],"classification":[132],"tasks":[133],"compared":[134],"current":[136],"state-of-the-art":[137],"deep":[138],"learning":[139],"architectures.":[140],"We":[141],"validate":[142],"reverse-engineered":[144],"detail":[149],"our":[150],"real-time":[151],"implementation":[152],"strategy":[153],"scoring":[155],"real-world":[156],"logs":[158],"within":[159],"large":[161],"enterprise.":[162],"In":[163],"4":[164],"h":[165],"actual":[167],"traffic,":[169],"model":[171],"discovered":[172],"at":[173],"least":[174],"five":[175],"potential":[176],"command-and-control":[177],"networks":[178],"commercial":[180],"vendor":[181],"tools":[182],"did":[183],"not":[184],"flag.":[185]},"counts_by_year":[{"year":2024,"cited_by_count":2},{"year":2023,"cited_by_count":4},{"year":2021,"cited_by_count":1}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
