Towards Robust Domain Generation Algorithm Classification
ACM Asia Conference on Computer and Communications Security (ASIA CCS), pp. 2–18
Abstract
In this work, we conduct a comprehensive study on the robustness of domain generation algorithm (DGA) classifiers. We implement 32 white-box attacks, 19 of which are very effective and induce a false-negative rate (FNR) of ≈ 100% on unhardened classifiers. To defend the classifiers, we evaluate different hardening approaches and propose a novel training scheme that leverages adversarial latent space vectors and discretized adversarial domains to significantly improve robustness. In our study, we highlight a pitfall to avoid when hardening classifiers and uncover training biases that can be easily exploited by attackers to bypass detection, but which can be mitigated by adversarial training (AT). In our study, we do not observe any trade-off between robustness and performance, on the contrary, hardening improves a classifier's detection performance for known and unknown DGAs. We implement all attacks and defenses discussed in this paper as a standalone library, which we make publicly available1 to facilitate hardening of DGA classifiers.
Authors 2
-
Arthur Drichel Aachen
Affiliation as printed
RWTH Aachen University, Aachen, Germany
-
Ulrike Meyer Aachen
Affiliation as printed
RWTH Aachen University, Aachen, Germany
Cited by 6 stored of 6
6 results
No patents citing this paper on Lens.org (checked 2026-10-06).
References 63
-
W2963250244details pending0citations
-
W2954590176details pending0citations
-
W4302282827details pending0citations
-
W4293580221details pending0citations
-
W3103331180details pending0citations
-
W2963857521details pending0citations
-
W3035736465details pending0citations
-
W3211999566details pending0citations