УДК 004.056.53 EDN: UHJPOY e-Library ID: 82707605

ПРИМЕНЕНИЕ МЕТОДОВ МАШИННОГО ОБУЧЕНИЯ ДЛЯ ПРОТИВОДЕЙСТВИЯ DGA-УГРОЗАМ В СИСТЕМЕ УПРАВЛЕНИЯ КАЧЕСТВОМ ИНФОРМАЦИОННОЙ БЕЗОПАСНОСТИ ПРЕДПРИЯТИЙ

🇷🇺 На русском

Для цитирования

Королев И.А., Кобелев Е.А., Булгакова Е.В., Кубанков А.Н. Применение методов машинного обучения для противодействия DGA-угрозам в системе управления качеством информационной безопасности предприятий // Информационно-экономические аспекты стандартизации и технического регулирования. 2025. № 4(85). С. 46–55.

Аннотация

В данной статье определяется понятие технологии DGA, проводится анализ существующих решений для распознавания её применения. Формируется набор моделей машинного обучения, подходящих для определения зараженных доменов, на основе сравнения и обучения которых разрабатывается нейронная сеть для автоматической классификации данных. Описаны этапы подготовки данных, построения бинарного классификатора и оценки его эффективности. Проведено сравнение моделей Random Forest, Gradient Boosting и Logistic Regression по метрикам точности, полноты, F1-меры и ROC AUC. Результаты показали высокую эффективность при комбинировании методов машинного обучения внутри нейронной сети, особенно с использованием Gradient Boosting. Разработанный алгоритм применим в реальном времени и может быть интегрирован в информационные системы для защиты сетевой инфраструктуры.

Ключевые слова

DGA ДОМЕН ХОСТ БОТНЕТ МАШИННОЕ ОБУЧЕНИЕ НЕЙРОННАЯ СЕТЬ БИНАРНАЯ КЛАССИФИКАЦИЯ

Об авторах

Королев И. А.

Королев И. А. — магистр, Финансовый университет при Правительстве РФ, ( Москва, Россия )

Кобелев Е. А.

Кобелев Е. А. — магистр, Финансовый университет при Правительстве РФ, ( Москва, Россия )

Булгакова Е. В.

Булгакова Е. В. — канд. юрид. наук, доцент, Московский университет МВД России имени В.Я. Кикотя, ( Москва, Россия )

Кубанков А. Н.

Кубанков А. Н. — профессор, д-р воен. наук, главный научный сотрудник, Российский институт стандартизации, ( Москва, Россия )

Список литературы

  1. 1. Галиахметов Д.Г. Сравнение алгоритмов классификации применительно к задаче обнаружения вредоносных доменных имен // Математические методы в технике и технологиях-ММТТ. 2019. Т. 12. С. 190–194.
  2. 2. Berman D.S., et al. A survey of deep learning methods for cyber security // Information. 2019. Т. 10, № 4. С. 122.
  3. 3. Бубнов Я.В., Иванов Н.Н. Обнаружение DGA доменов и предотвращение botnet средствами Q-обучения для POMDP // Доклады Белорусского государственного университета информатики и радиоэлектроники. 2021. Т. 19, № 2. С. 91–99.
  4. 4. Antonakakis M., Perdisci R. From throw-away traffic to bots: detecting the rise of DGA-based malware // In Proceedings of the 21st USENIX Security Symposium. 2012, pp. 491–506.
  5. 5. Binkley J.R., Singh S. An algorithm for anomaly-based botnet detection // SRUTI. 2006. № 6. pp. 43–48
  6. 6. Li Y., Xiong K. Machine Learning Framework for Domain Generation Algorithm-Based Malware Detection // IEEE Access. 2019. C. 32765–32782.
  7. 7. Alazab M., Tang M. Deep Learning Applications for Cyber Security. Springer Nature Switzerland, 2019. 246 c.
  8. 8. AsSadhan B., Moura J.M.F., Lapsley D., et al. Detecting botnets using command and control traffic // In 2009 8th IEEE International Symposium on Network Computing and Applications. IEEE, 2009. С. 156–162.
  9. 9. Malwarebytes Labs 2019 State of Malware Report. URL: https://resources.malwarebytes.com/files/2019/01/MalwarebytesLabs-2019-State-of Malware- Report-2.pdf (дата обращения:15.05.2025).
  10. 10. Wang Z., Jia Z., Zhang B. A detection scheme for DGA domain names, based on SVM // In 2018 International Conference on Mathematics, Modelling, Simulation and Algorithms (MMSA 2018). 2018. C. 257–263.
  11. 11. Why Machine Learning Models Degrade in Production [Электронный ресурс]. URL: https://towardsdatascience.com/ why-machine-learning-models-degrade-in-production-d0f2108e9214 (дата обращения: 15.05.2025).
🇬🇧 In English

APPLICATION OF MACHINE LEARNING METHODS TO COUNTER DGA THREATS IN THE ENTERPRISE INFORMATION SECURITY QUALITY MANAGEMENT SYSTEM

For citation

Korolev I.A., Kobelev E.A., Bulgakova E.V., Kubankov A.N. Application of Machine Learning Methods to Counter DGA Threats in the Enterprise Information Security Quality Management System. Information and Economic aspects of standardization and technical regulation. 2025; 4(85): 46–55. (In Russ.)

Abstract

This article defines the concept of DGA technology, analyzes existing solutions for recognizing its application, and forms a set of machine learning models suitable for identifying infected domains. Based on the model comparison and training, a neural network is developed for automatic data classification. Methods used: This study focuses on the development and implementation of an algorithm for detecting DGA domains using machine learning models. It describes the binary classifier setup, including feature transformation, model training, and performance interpretation. Results of the study: Three models - Random Forest, Gradient Boosting, and Logistic Regression - were compared. Gradient Boosting showed the best performance (ROC AUC = 0.998). Practical value: The proposed solution is suitable for integration into DNS monitoring systems to enhance information security. The developed algorithm can be applied in real time and integrated into information systems to protect network infrastructure.

Keywords

DGA DOMAIN HOST BOTNET MACHINE LEARNING NEURAL NETWORK BINARY CLASSIFICATION

About the authors

Korolev I. А.

Korolev I. А. — MSc, Financial University under the Government of the Russian Federation, ( Moscow, Russia )

Kobelev E. A.

Kobelev E. A. — MSc, Financial University under the Government of the Russian Federation, ( Moscow, Russia )

Bulgakova E. V.

Bulgakova E. V. — Ph.D., Associate Professor, Moscow University of the Ministry of Internal Affairs of Russia named after V.Ya. Kikot, ( Moscow, Russia )

Kubankov A. N.

Kubankov A. N. — Professor, Doctor of Military Sciences, Chief Researcher, Russian Standardization Institute, ( Moscow, Russia )

References

  1. 1. Galiakhmetov D.G. Sravnenie algorytmov classifikacii primenitel’no k zadache obnaruzhenya vredonosnykh domennykh imyon. Matematicheskie metody v tekhnike i tekhnologiyah-MMTT. 2019; 12: 190–194. (In Russ.).
  2. 2. Berman D.S., et al. A survey of deep learning methods for cyber security // Information. 2019. Т. 10, № 4. С. 122.
  3. 3. Bubnov Y.V., Ivanov N.N. Obnaruzheniye DGA domenov i predotvrascheniye botnet sredstvami Q-obucheniya dlya POMDP. Doklady Belorusskogo gosudarstvennogo universiteta informatiki i radioelektroniki. 2021; 19(2): 91–99. (In Russ.).
  4. 4. Antonakakis M., Perdisci R. From throw-away traffic to bots: detecting the rise of DGA-based malware // In Proceedings of the 21st USENIX Security Symposium. 2012, pp. 491–506.
  5. 5. Binkley J.R., Singh S. An algorithm for anomaly-based botnet detection // SRUTI. 2006. № 6. pp. 43–48
  6. 6. Li Y., Xiong K. Machine Learning Framework for Domain Generation Algorithm-Based Malware Detection // IEEE Access. 2019. C. 32765–32782.
  7. 7. Alazab M., Tang M. Deep Learning Applications for Cyber Security. Springer Nature Switzerland, 2019. 246 c.
  8. 8. AsSadhan B., Moura J.M.F., Lapsley D., et al. Detecting botnets using command and control traffic // In 2009 8th IEEE International Symposium on Network Computing and Applications. IEEE, 2009. С. 156–162.
  9. 9. Malwarebytes Labs 2019 State of Malware Report. URL: https://resources.malwarebytes.com/files/2019/01/MalwarebytesLabs-2019-State-of Malware- Report-2.pdf (дата обращения:15.05.2025).
  10. 10. Wang Z., Jia Z., Zhang B. A detection scheme for DGA domain names, based on SVM // In 2018 International Conference on Mathematics, Modelling, Simulation and Algorithms (MMSA 2018). 2018. C. 257–263.
  11. 11. Why Machine Learning Models Degrade in Production. URL: https://towardsdatascience.com/ why-machine-learning-models-degrade-in-production-d0f2108e9214 (дата обращения: 15.05.2025).