{ "namespace": "dga", "expanded": "Domain-Generation Algorithms", "description": "A taxonomy to describe domain-generation algorithms often called DGA. Ref: A Comprehensive Measurement Study of Domain Generating Malware Daniel Plohmann and others.", "version": 2, "predicates": [ { "value": "generation-scheme", "expanded": "Generation scheme used for the DGA", "uuid": "afdbf771-7daa-5553-bb72-26fe0fa9396c" }, { "value": "seeding", "expanded": "Seeding scheme used for the DGA", "uuid": "5c143246-9c21-5d45-8d2f-88199be76771" } ], "values": [ { "predicate": "generation-scheme", "entry": [ { "value": "arithmetic", "expanded": "Arithmetic", "description": "Calculate a sequence of values that either have a direct ASCII representation usable for a domain name or designate an offset in one or more hard- coded arrays, constituting the alphabet of the DGA. ", "uuid": "4c64aef8-7105-50a6-b522-6900d5afc9a9" }, { "value": "hash", "expanded": "Hash", "description": "Use the hexdigest representation of a hash to produce the domain.", "uuid": "1c9489a9-81e7-5d92-bb7b-938ae3ef985d" }, { "value": "wordlist", "expanded": "Wordlist", "description": "Concatenate a sequence of words from one or more wordlists, resulting in less randomly appealing and thus more camouflaging domains", "uuid": "58a135a5-a039-5933-9887-50d24566e0e8" }, { "value": "permutation", "expanded": "Permutation", "description": "derive all possible AGDs (Algorithmically-Generated Domain) through permutation of an initial domain name.", "uuid": "447f04d7-d8e0-581b-9a67-8ecadcdb4374" } ] }, { "predicate": "seeding", "entry": [ { "value": "time-dependent", "expanded": "The DGA uses temporal information in the seeding for its domain generation, resulting in sets of domains with certain validity time spans.", "uuid": "cdede597-37ed-5dac-8f12-03a337f2603a" }, { "value": "time-independent", "expanded": "The DGA does not rely on temporal information in the seeding for its domain generation, resulting in a single set of domains.", "uuid": "64783d82-9fc3-56e0-ab2a-6415d8a32362" }, { "value": "deterministic", "expanded": "Given the implementation of the DGA and a seed, its full set of possible domains can be calculated at any point in time.", "uuid": "6a2f4b30-6c9c-5171-a9b7-ef91aed77f87" }, { "value": "non-deterministic", "expanded": "Domains depend on unpredictable seed input, e.g. on external dynamic information that can be published at a later time (e.g. via posting on social media), on data specific to the system it is executed on, or on arbitrary non-predictable PRNG output.", "uuid": "8ced3be7-1d88-509a-92dc-f9883c293fb7" } ] } ], "uuid": "667e9c12-96f1-5f5b-9bc5-c480e43b8dfd" }