DGA Malware Deep Learning Detection and its Optimization with Novel Activation Function

Clicks: 1
ID: 313258
2023
Article Quality & Performance Metrics
Overall Quality
Not rated
Combines reader engagement with the AI quality analysis. This article has not been analysed, so there is no overall score — reader engagement is measured and shown alongside.
AI Quality Assessment
Not analyzed
Readership in this journal

Ranked #666 of 705 articles by views in Journal of Computing & Biomedical Informatics

Most read Least read

Bar heights use a square-root scale. Only the 120 most-read articles are drawn; the journal has 705 in total.

Mint this article as an NFT
Not yet minted

Create a permanent, verifiable on-chain record of this article on the Scimatic Network. The NFT is held in your Journament account, and you can withdraw it to your own wallet at any time.

5 SUSD one-off · no wallet required
Abstract
APTs mutually coupled with Cyber Kill Chains (CKC) and its specified phase of malicious command and control (C2) servers. These C2 servers maintain communication using malicious domains with a specially crafted malware called Domain Generating Algorithm (DGA). The DGA malware is available in different compositions and complexities associated with various APTs as well as DGA families. DGA detection is achieved using different Machine Learning (ML) models and recently DGA detection is further improved with Deep Learning (DL) models. These trained DL models have solved DGA detection using text classification, successfully classifying legitimate domains from malicious domains. DL models' optimal detection is further optimized by tuning DL key functions, one such key function is the Activation Function (AF). Primarily AF provides the property of non-linearity which is very effective in mapping and solving real-world problems. Recently reported AFs in literature are based on their superior performance in text classification are identified and analysed in these optimal DL models. Due to Long Short Term Memory (LSTM) and Attention models successful detection in text classification, LSTM with Attention is implemented for deeper analysis of these reported AFs. In this research paper, the DGA detection DL models have been simulated with the default AFs and performance of proposed AF has been tested against default AFs. The proposed AF Zash outperformed the ReLU, Hyper-Tangent (Tanh) and Swish AFs in terms of their polynomial properties. Sparse activations being core property of ReLU may miss some of significant weight updates in comparison to dense activations of exponential fixed shaped Tanh and Swish AFs. Results have shown that the proposed Zash AF have overcome the sparse activations of ReLU and has achieved proficient results in dense activations over Tanh and Swish AFs. This novel AF has shown better detection results in training and validation for text based character classification using dense activations.
Reference Key
imported_1777060089_69ebc8f997df0 Use this key to autocite in the manuscript while using SciMatic Manuscript Manager or Thesis Manager
Authors Adnan Rashdi
Journal Journal of Computing & Biomedical Informatics
Year 2023
DOI
DOI not found
URL
Keywords Keywords not found

Citations

No citations found. To add a citation, contact the admin at info@scimatic.org

No comments yet. Be the first to comment on this article.