Botnet Detection: A System for Identifying DGA-based Botnets Using LightGBM.

Saved in:
Bibliographic Details
Title: Botnet Detection: A System for Identifying DGA-based Botnets Using LightGBM.
Authors: Mohamad, Mumtazimah1 mumtaz@unisza.edu.my, Hamid, Nazirah Abd1 nazirah@unisza.edu.my, Ghaleb, Sanaa1 sanaaabduljabbar@unisza.edu.my, Satar, Siti Dhalila Mohd1 sitidhalila@unisza.edu.my, Safei, Suhailan2 suhailan@unisza.edu.my, Wan Hamzah, Wan Mohd Amir Fazamin1 amirfazamin@unisza.edu.my
Source: IAENG International Journal of Applied Mathematics. Jun2026, Vol. 56 Issue 6, p2291-2300. 10p.
Subjects: Botnets, Machine learning, Internet security, Boosting algorithms, Anomaly detection (Computer security)
Abstract: Botnets using domain generation algorithms (DGAs) pose a major challenge to anomaly detection, as they generate large numbers of random domains to evade blacklists. Traditional methods struggle to classify these domains effectively due to their dynamic nature. This study proposes a robust solution to address the challenges posed by DGA-based botnets by developing an innovative machine learning-based model for domain name classification. The model leverages the light gradient boosting algorithm (LightGBM) and integrates n-gram features to enhance the detection of malicious DGA domains. This approach offers superior accuracy, adaptability, and efficiency in identifying and classifying anomalous domain names, achieving 96% precision when detecting true DGA domains. This system represents a significant advancement in cybersecurity and anomaly detection. [ABSTRACT FROM AUTHOR]
Copyright of IAENG International Journal of Applied Mathematics is the property of International Association of Engineers (IAENG) and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
Description
Abstract:Botnets using domain generation algorithms (DGAs) pose a major challenge to anomaly detection, as they generate large numbers of random domains to evade blacklists. Traditional methods struggle to classify these domains effectively due to their dynamic nature. This study proposes a robust solution to address the challenges posed by DGA-based botnets by developing an innovative machine learning-based model for domain name classification. The model leverages the light gradient boosting algorithm (LightGBM) and integrates n-gram features to enhance the detection of malicious DGA domains. This approach offers superior accuracy, adaptability, and efficiency in identifying and classifying anomalous domain names, achieving 96% precision when detecting true DGA domains. This system represents a significant advancement in cybersecurity and anomaly detection. [ABSTRACT FROM AUTHOR]
ISSN:19929978