Current - Issue
Year 2026 · Volume 5 · Issue 3
Case Study
Machine Learning-Based Classification of Encrypted Network Traffic and Domain Generation Algorithm (DGA) Threats
Dr. Channakeshava RN1
1 Associate Professor, Department of Computer Science, HPPC Government First Grade College, Challakere, Karnataka, India.
Published Online: September-December 2026
Pages: 12-17
Cite this article
↗ https://www.doi.org/10.59256/indjcst.20260503003References
1. M. Ring, S. Wunderlich, D. Scheuring, D. Landes, and A. Hotho, "A survey of network-based intrusion detection systems using machine learning," ACM Computing Surveys (CSUR), vol. 52, no. 6, pp. 1–39, 2019.
2. S. Pan, R. Yu, and X. Wang, "A survey of network flow classification using machine learning," Journal of Network and Computer Applications, vol. 156, p. 102561, 2020.
3. P. Garciaodoro, M. Zolanvari, and R. Jain, "Machine learning for IoT security: Current status and future challenges," IEEE Internet of Things Journal, vol. 8, no. 15, pp. 12110–12128, 2021.
4. A. Anderson, S. Schrittwieser, and J. Morales, "Detecting command and control channels in encrypted network traffic," IEEE Transactions on Information Forensics and Security, vol. 14, no. 6, pp. 1452–1465, 2019.
5. T. Van Ede, R. De Boer, A. Continella, J. Van Der Ham, I. Peter, and M. Alnafessah, "Flowprint: Semi-supervised mobile-app fingerprinting on encrypted network traffic," in 29th USENIX Security Symposium, pp. 915–932, 2020.
6. D. Aris, P. Laskov, and K. Rieck, "Malicious traffic identification using flow metadata and statistical profiling," IEEE Transactions on Dependable and Secure Computing, vol. 17, no. 4, pp. 812–825, 2020.
7. CERT.org, "Analyzing encrypted network communications for malicious indicators," Software Engineering Institute Technical Report, 2023.
8. J. Sterling and K. Sundaram, "Encrypted traffic classification using deep learning: A comparative survey," Computers & Security, vol. 112, p. 102512, 2022.
9. H. S. Anderson and P. Roth, "EMBER: An open dataset for training machine learning malware detectors," arXiv preprint arXiv: 1804.04637, 2018.
10. J. Saxe and K. Berlin, "Deep neural network based malware detection using two dimensional binary program characterizations," in 11th International Conference on Malicious and Unwanted Software (MALWARE), pp. 1–8, 2016.
11. I. Goodfellow, Y. Bengio, and A. Courville, Deep Learning, MIT Press, 2016.
12. S. Hochreiter and J. Schmidhuber, "Long short-term memory," Neural Computation, vol. 9, no. 8, pp. 1735–1780, 1997.
13. N. Japkowicz and M. Shah, Evaluating Learning Strategies for Classifying Rare Classes, Cambridge University Press, 2011.
14. L. Bilge, D. Balzarotti, W. Robertson, E. Kirda, and C. Kruegel, "DISSECT: Interrogating malicious domain names," in Proceedings of the 18th ACM Conference on Computer and Communications Security (CCS), pp. 335–348, 2011.
15. B. Yu, J. Pan, J. Hu, and S. Liu, "Character level-based detection of DGA domain names," in IEEE International Conference on Intelligence and Security Informatics (ISI), pp. 100–105, 2018.
16. E. Mariconti et al., "Mambrino's helm: Making DGA-based malware detection robust against re-engineering," in 24th IEEE Symposium on Security and Privacy (S&P), pp. 381–397, 2017.
17. M. Woodbridge, H. S. Anderson, A. Ahuja, and D. Grant, "Predicting domain generation algorithms with long short-term memory networks," arXiv preprint arXiv: 1611.00791, 2016.
18. Q. Liu, Y. Li, and Z. Qu, "TADDAG: Translating and detecting domain generation algorithms via attention mechanisms," Computers & Security, vol. 120, p. 102810, 2022.
19. F. Pedregosa et al., "Scikit-learn: Machine learning in Python," Journal of Machine Learning Research, vol. 12, pp. 2825–2830, 2011.
20. T. Chen and C. Guestrin, "XGBoost: A scalable tree boosting system," in Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pp. 785–794, 2016.
2. S. Pan, R. Yu, and X. Wang, "A survey of network flow classification using machine learning," Journal of Network and Computer Applications, vol. 156, p. 102561, 2020.
3. P. Garciaodoro, M. Zolanvari, and R. Jain, "Machine learning for IoT security: Current status and future challenges," IEEE Internet of Things Journal, vol. 8, no. 15, pp. 12110–12128, 2021.
4. A. Anderson, S. Schrittwieser, and J. Morales, "Detecting command and control channels in encrypted network traffic," IEEE Transactions on Information Forensics and Security, vol. 14, no. 6, pp. 1452–1465, 2019.
5. T. Van Ede, R. De Boer, A. Continella, J. Van Der Ham, I. Peter, and M. Alnafessah, "Flowprint: Semi-supervised mobile-app fingerprinting on encrypted network traffic," in 29th USENIX Security Symposium, pp. 915–932, 2020.
6. D. Aris, P. Laskov, and K. Rieck, "Malicious traffic identification using flow metadata and statistical profiling," IEEE Transactions on Dependable and Secure Computing, vol. 17, no. 4, pp. 812–825, 2020.
7. CERT.org, "Analyzing encrypted network communications for malicious indicators," Software Engineering Institute Technical Report, 2023.
8. J. Sterling and K. Sundaram, "Encrypted traffic classification using deep learning: A comparative survey," Computers & Security, vol. 112, p. 102512, 2022.
9. H. S. Anderson and P. Roth, "EMBER: An open dataset for training machine learning malware detectors," arXiv preprint arXiv: 1804.04637, 2018.
10. J. Saxe and K. Berlin, "Deep neural network based malware detection using two dimensional binary program characterizations," in 11th International Conference on Malicious and Unwanted Software (MALWARE), pp. 1–8, 2016.
11. I. Goodfellow, Y. Bengio, and A. Courville, Deep Learning, MIT Press, 2016.
12. S. Hochreiter and J. Schmidhuber, "Long short-term memory," Neural Computation, vol. 9, no. 8, pp. 1735–1780, 1997.
13. N. Japkowicz and M. Shah, Evaluating Learning Strategies for Classifying Rare Classes, Cambridge University Press, 2011.
14. L. Bilge, D. Balzarotti, W. Robertson, E. Kirda, and C. Kruegel, "DISSECT: Interrogating malicious domain names," in Proceedings of the 18th ACM Conference on Computer and Communications Security (CCS), pp. 335–348, 2011.
15. B. Yu, J. Pan, J. Hu, and S. Liu, "Character level-based detection of DGA domain names," in IEEE International Conference on Intelligence and Security Informatics (ISI), pp. 100–105, 2018.
16. E. Mariconti et al., "Mambrino's helm: Making DGA-based malware detection robust against re-engineering," in 24th IEEE Symposium on Security and Privacy (S&P), pp. 381–397, 2017.
17. M. Woodbridge, H. S. Anderson, A. Ahuja, and D. Grant, "Predicting domain generation algorithms with long short-term memory networks," arXiv preprint arXiv: 1611.00791, 2016.
18. Q. Liu, Y. Li, and Z. Qu, "TADDAG: Translating and detecting domain generation algorithms via attention mechanisms," Computers & Security, vol. 120, p. 102810, 2022.
19. F. Pedregosa et al., "Scikit-learn: Machine learning in Python," Journal of Machine Learning Research, vol. 12, pp. 2825–2830, 2011.
20. T. Chen and C. Guestrin, "XGBoost: A scalable tree boosting system," in Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pp. 785–794, 2016.
Related Articles
2026
Artificial Intelligence in Learning and Teaching
2026
Admin Assist: An AI – Driven Configuration and Orchestration for Enterprise Application
2026
Enhancing Blood Group Identification using pigeon inspired optimization: An Innovative Approach
2026
Eco-Genius: Power Up Smart, Power Down Waste
2026
Crowd-Sourced Disaster Response and Rescue Assistant
2026
Unveiling Deepfake Detection Using Vision Transformers: A Survey and Experimental Study
Share Article
Or copy link
https://www.indjcst.com/archives/machine-learning-based-classification-of-encrypted-network-traffic-and-domain-generation-algorithm-dga-threats
*Instagram doesn't support direct link sharing from web. Copy the link and share it in your Instagram story or post.