Skip to main content
Advertisement
Browse Subject Areas
?

Click through the PLOS taxonomy to find articles in your field.

For more information about PLOS Subject Areas, click here.

< Back to Article

An end-to-end framework for private DGA detection as a service

Fig 2

Illustration of the use of a DGA.

The botmaster and malware on an infected client generate the same list of domain names. The botmaster registers a domain from the list. The malware attempts to resolve each domain from the list with the DNS until it finds the registered domain and a connection between the infected client and the C&C is successfully established.

Fig 2

doi: https://doi.org/10.1371/journal.pone.0304476.g002