<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Countering Cybersecurity Threats with AI</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Nemanja Veselinović</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Miloš Milašinović</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Miloš Jovanović</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Aca Aleksić</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Nenad Biga</string-name>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Academy of Technical and Art Applied Studies, School of Electrical and Computer Engineering</institution>
          ,
          <addr-line>Belgrade</addr-line>
          ,
          <country country="RS">Serbia</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Belgrade Metropolitan University, Faculty of Information Technology</institution>
          ,
          <addr-line>Tadeuša Košćuška 63, Belgrade</addr-line>
          ,
          <country country="RS">Serbia</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Graduate School of Business, La Salle University</institution>
          ,
          <addr-line>Philadelphia</addr-line>
          ,
          <country country="US">United States of America</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>This paper discusses the role of artificial intelligence in cyber attacks. Because of all the specifics that AI technology brings with it, what is characteristic of it is its relationship with cyber risks. AI technology has a twofold efect on cyber security: it can threaten it, and it can also contribute to it. This paper discusses the role of artificial intelligence in cyber attacks. It also talks about machine learning and some of the methods, as well as deep learning methods. Here, various researches are analyzed and the best artificial intelligence methods are presented when it comes to cyber security.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;AI</kwd>
        <kwd>Cybersecurity</kwd>
        <kwd>Machine Learning</kwd>
        <kwd>SVM</kwd>
        <kwd>Spam</kwd>
        <kwd>Threat</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>tems become more flexible and efective, which involves
adapting to changes in the environment to reduce the
impacts that have occurred.</p>
      <p>Recently, researchers have presented several
researches in the field of artificial intelligence and cyber
security. some of them only focused on adopting
machine learning methods for cyber problems while other
research remained focused on deep learning methods. In
addition, there is a lack of literature dealing with
nefarious uses of AI.</p>
      <p>Cyber security is the development of defensive strategies
that protect computer assets, networks, data and
programs from unauthorized access, alteration or
destruction. Due to the great advancement of information and
communication technologies, new cyber security threats
are emerging and changing rapidly. Cybercriminals are
adopting new techniques that make their attacks faster
and more extensive.</p>
      <p>Thus, there is a demand for more adaptable and
compact cyber defense systems that can detect a wide range
of threats in real time. In recent years, the adoption 2. The Impact of Artificial
of artificial intelligence (AI) techniques has grown and Intelligence on Cyber Security
continues to play an essential role in detecting and
preventing cyber threats. While the AI agenda was proposed Defining AI can have two approaches. First, it is a
sciin the 1950s, it has grown rapidly in recent years and now ence that seeks to develop intelligent machines in which
afects all forms of communities and occupations. scientists apply information, decision, logic and learning</p>
      <p>
        This trend also afects the field of cyber security where to make machines intelligent and able to think, learn,
artificial intelligence is used for both attack and defense decide and act while trying to solve a problem, just as it
in cyberspace. Many fields benefit from artificial intel- does human reason.
ligence, such as natural language processing, gaming, On the other hand, scientists refer to AI as a science
education, healthcare, manufacturing and more. From that researches and develops methods to solve complex
an attack perspective, cyber threats can use artificial in- problems that are impossible to solve without adopting
telligence to improve the excellence and scale of their intelligence [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ].
attacks. For example, scientists can build an AI system for
      </p>
      <p>From a defense point of view, artificial intelligence is real-time analysis and decision-making based on huge
used to improve defense strategies, so that defense sys- amounts of data. In recent years, AI has led to advances in
many scientific and technological fields, such as
computerized work, natural language processing, expert systems,
image recognition, and more.</p>
      <p>The rapid development of computer technology and
the Internet has a significant impact on people’s daily
life and work. however, it has also created many new
cybersecurity problems: First, the proliferation of data
means that new, short-lived species and highly adap- builds a baseline of what is normal. From there, any
tive threats are becoming quite normal. Third, threats deviations can be observed to detect attacks.
currently threaten various propagation, infection, and Artificial intelligence techniques are an emerging area
evasion techniques; therefore, they are dificult to predict of research that improves security measures for
cyand detect. berspace.</p>
      <p>
        It takes a lot of time, money and efort to produce and Many AI methods are used to deal with threats,
includimplement an algorithm. also, hiring or training people ing intelligent agents, neural networks, computational
in this field is dificult and expensive. many deviations intelligence, artificial immune systems, data mining,
patand threats occur and continue to spread. so artificial tern recognition, ML, DL, and others. However, among
intelligence based methods are expected to keep pace these techniques, ML and DL have recently attracted
with these cyber security issues [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. much attention and achieved the most achievements in
the fight against cyber threats [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ].
      </p>
      <sec id="sec-1-1">
        <title>2.1. Positive Use of AI</title>
      </sec>
      <sec id="sec-1-2">
        <title>2.2. Disadvantages and Limitations of</title>
      </sec>
      <sec id="sec-1-3">
        <title>Using AI</title>
        <p>Based on its large automation and data analysis
capabilities, AI can be used to analyze large amounts of data
with accuracy, speed and eficiency. An artificial intelli- The advantages highlighted above are only a fraction of
gence system can use existing information and recognize how artificial intelligence can help cyber security, but
threats from the past to identify similar attacks in the the application of this technology has some limitations.
future, even if they change. artificial intelligence has Datasets: Creating an AI system requires a significant
several advantages when it comes to cyber security in number of input samples, and obtaining and
processthe following aspects. ing the samples can be time-consuming and
resource</p>
        <p>
          AI can detect new attack changes: Conventional tech- intensive. Resource Requirements: Building and
mainnology mostly relies on known attackers and attacks, taining the underlying system requires a tremendous
while leaving room for blind spots when detecting events amount of resources, including data, memory, and
comin new attacks. The limitations of old defense technology puting power. the qualified resources necessary to
impleare now being addressed through intelligent technology. ment this technology require significant costs [
          <xref ref-type="bibr" rid="ref2">2</xref>
          ].
        </p>
        <p>
          For example, privileged activity on an intranet can be False alarms: Frequent false alarms are a problem for
monitored, and any significant mutation in privileged users because they disrupt business by possibly delaying
access operations can indicate a potential threat. If the any necessary response and generally afecting eficiency.
detection is successful, the machine will become more The fine-tuning process is a compromise between
reducsensitive to detecting similar patterns in the future. With ing false alarms and maintaining a level of security.
more data, the machine can better learn and adapt to Attacks on AI-based systems: Attackers can use
vardetect faster and more accurate operations [
          <xref ref-type="bibr" rid="ref2">2</xref>
          ]. ious attack techniques that target AI systems, such as
        </p>
        <p>This is very useful as cyber attacks become more so- adversarial inputs, model theft, and data poisoning. One
phisticated and hackers develop new and innovative ap- important aspect to consider is the nefarious use of AI.
proaches. This technology will also be used as a way to improve</p>
        <p>AI can handle large volumes of data: AI can improve threats. For example, malicious actors can use ML
technetwork security by developing autonomous security niques to generate a variant of malware that is dificult
systems to detect attacks and respond to breaches. The to detect at machine speed. artificial intelligence could
amount of security alerts that appear every day can be better personalize the phishing scheme and increase the
overwhelming for security groups. scope of the attack, making the attack more likely to</p>
        <p>
          Automated threat detection and response has helped succeed [
          <xref ref-type="bibr" rid="ref2">2</xref>
          ].
reduce the work of network security professionals and
can help detect threats more efectively than other
methods. When a large amount of data is created and trans- 3. Artificial Intelligence
ferred over the network every day, network security pro- Methodology for Cyber Security
fessionals will gradually have dificulty tracking and
identifying attack factors quickly and reliably [
          <xref ref-type="bibr" rid="ref2">2</xref>
          ]. This section provides an overview of learning algorithms,
        </p>
        <p>This is where artificial intelligence can help by expand- a core concept of AI. In addition, section presents a brief
ing the monitoring and detection of suspicious activity. introduction on ML, DL, and bio-inspired computational</p>
        <p>An AI security system can learn to respond better to methods frequently used in the field of cybersecurity.
threats: AI helps detect threats based on application
behavior and network-wide activity. An AI security system
learns about regular network trafic and behavior and</p>
      </sec>
      <sec id="sec-1-4">
        <title>3.1. Learning Algorithms</title>
        <p>
          AI is a branch of computer science that seeks to produce a
new type of intelligent automaton that reacts like human
intelligence. in order to achieve this goal, machines must
learn. To be more accurate, we need to train the
computer using learning algorithms. learning algorithms help
improve task performance through experiential training
and learning. so far there are three main types of learning
algorithms we use to train machines:
to ML methods, DL methods also have supervised
learning, unsupervised learning, and assisted learning. Typical
DL algorithms often used in the cyber security domain
are: Feedforward Neural Networks (FNN), Recurrent
Neural Networks (RNN), Complex Autoencoders (SAE),
Generative Adversarial Networks (GAN), Restricted
Boltzmann Machines (RBM), Convolutional Neural networks
(CNN), deep belief networks (DBN) and ensemble DL
networks (EDLN) [
          <xref ref-type="bibr" rid="ref5">5</xref>
          ].
• Supervised learning: This type requires a train- 3.4. Bio-inspired Computational Methods
ing process with a large dataset that is pre-labeled.
        </p>
        <p>
          These learning algorithms are often used as a clas- Bio-inspired computing is a branch of AI that has been
sification engine or a regression engine. one of the most studied in recent years. It is a collection
• Unsupervised Learning: Unlike supervised of intelligent algorithms and methods that adopt
biolearning, unsupervised learning algorithms use inspired behaviors and features to solve a wide range of
unlabeled data sets for training. These ap- complex academic and real-world domain problems.
proaches are often used for data clustering, den- Among many biologically inspired methods, the
folsity estimation, or dimensionality reduction. lowing techniques are most commonly used in the cyber
security domain: Ant Colony Optimization (ACO),
Parti• Reinforcement Learning: Reinforcement learn- cle Swarm Optimization (PSO), Evolutionary Strategies
ing is a type of learning algorithm that learns the (ES), Genetic Algorithms (GA), and Artificial Immune
best actions based on rewards or punishment. Re- System (AIS) [
          <xref ref-type="bibr" rid="ref6">6</xref>
          ].
inforcement learning is useful in situations where
data is limited or not provided [
          <xref ref-type="bibr" rid="ref3">3</xref>
          ].
        </p>
      </sec>
      <sec id="sec-1-5">
        <title>3.2. Machine Learning Methods</title>
        <p>
          Machine learning (ML) is a branch of artificial
intelligence that aims to strengthen systems by using data to
learn and improve without explicit programming. ML has Recently, scientists have proposed numerous techniques
strong ties to mathematical techniques that enable the that used AI methods to detect or categorize malware,
process of extracting information, drawing conclusions phishing, network intrusion detection, and spam attacks;
from data, and discovering patterns. There are diferent counter Advanced Persistent Threat (APT); and identify
types of ML algorithms, but they can be classified into domains generated by Domain Generation Algorithms
three main categories: unsupervised learning, supervised (DGA). This part divides the literature into four main
learning, and assisted learning. In the field of computer groups: malware identification; network intrusion
desecurity, standard ML algorithms are decision trees (DT), tection; phishing and SPAM identification; and others,
support vector machines (SVM), association rule (AR) which compromises the fight against APT and the
identialgorithms, ensemble learning (EL), k-means clustering ifcation of DGA.
and principal component analysis (PCA), Bayesian
algorithms, k-nearest neighbor (KNN), random forest (RF) 4.1. Malicious Software Identification
[
          <xref ref-type="bibr" rid="ref4">4</xref>
          ].
        </p>
      </sec>
    </sec>
    <sec id="sec-2">
      <title>4. Artificial Intelligence-Based</title>
    </sec>
    <sec id="sec-3">
      <title>Approaches to Defense Against</title>
    </sec>
    <sec id="sec-4">
      <title>Cyberspace Attacks</title>
      <sec id="sec-4-1">
        <title>3.3. Deep Learning Methods</title>
        <p>Deep learning (DL) is a subfield of ML and uses data to
teach computers how to do things that only humans are
capable of. His motivation lies in the working
mechanisms of the human brain and neurons for signal
processing. The core of deep learning is that if we construct more
extensive neural networks and train them with as much
data as possible, their performance continues to increase.</p>
        <p>The most important advantage of DL over conventional
ML is its superior performance on large datasets. Similar
Malware is a general term for many types of malicious
software, such as viruses, Trojan horses, exploit worms,
retroviruses, botnets, and today, malware is a popular
method of cyber-attack. The impact of malware on digital
society is very large, so much research has been done on
adopting AI techniques to prevent and at least mitigate
malware. The latest contributions use intelligence to
detect and prevent malware.</p>
        <p>
          The proposed method used logistic regression,
support vector machine and random forest classifier and was
run on the RIPE benchmark suite for experiments. The
authors in [
          <xref ref-type="bibr" rid="ref7">7</xref>
          ] reported that the framework has a true
positive rate of 99% with a false positive rate of less than 5%.
        </p>
        <p>
          Meanwhile, scientists have presented a framework for Al-Yaseen et al. [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ] combined an extreme learning
malware classification and detection using data mining machine with modified k-means as a model for IDS and
and ML classification. In that paper, both signature-based a support vector machine (SVM). Using the KDD’99 Cup
and anomaly-based features for detection were analyzed. dataset, their model archived results of up to 95.75%
acExperimental results showed that the proposed method curacy and 1.87% false alarms. Meanwhile, Kabir et al.
inis better than other similar methods. troduced a least square support vector machine (LS-SVM)
        </p>
        <p>
          Another approach used operation codes (OpCode), k- sampling-based method for an intrusion detection
sysnearest neighbors (KNN), and support vector machine tem. The proposed methodology was confirmed through
(SVM) as ML classifiers for malware classification. Op- the KDD’99 Cup data set and obtained real performance
Code is represented as a graph and embedded in its own in terms of eficiency [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ]. Introduced a fuzzy-based
space; then, a single classifier or ensemble of classifiers semi-supervised learning approach for IDS. the paper
was used to classify each vector as malicious or benign. used unlabeled samples with the help of a supervised
The empirical result showed that the proposed model is learning algorithm to improve the performance of the
efective with low false alarm rate and high detection classifier. The algorithm was tested on the KDD’99 Cup
rate [
          <xref ref-type="bibr" rid="ref7">7</xref>
          ]. dataset and outperformed other benchmark algorithms.
        </p>
        <p>
          Later, Ie et al. has built a deep learning architecture for Thing to consider is the use of swarm intelligence (SI)
intelligent malware detection. In this paper, they used for IDS. Botes et al. [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ] presented a new method, namely
AutoEncoder with Multi-Layer Restricted Boltzmann Ma- Ant Miner Classification (ATM), which is a decision tree
chines (RBM) to detect unknown malware [
          <xref ref-type="bibr" rid="ref8">8</xref>
          ]. that uses ACO instead of conventional techniques, such
        </p>
        <p>
          A recent research trend in malware detection is fo- as C4.5 and CART , for intrusion detection. Using the
cused on mobile malware in general and Android mal- NSL-KDD datasets, their approach achieved an accuracy
ware in particular. Machine learning, along with deep of 65% and a false alarm rate of 0% [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ].
learning, has been a significant advance in this field. a In a later study, IDS was presented using binary PSO
deep convolutional neural network (CNN) is adopted for and KNN. The proposed method consists of feature
semalware identification. The raw sequence of operations lection and classification steps. Based on the obtained
from the disassembled program was used to classify the results, the algorithm showed excellent performance, and
malware. The authors in [
          <xref ref-type="bibr" rid="ref9">9</xref>
          ] used a support vector ma- the proposed hybrid algorithm raised the accuracy
genchine (SVM) and the most significant permissions from erated by KNN up to 2% [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ].
all permission data to distinguish between benign and In a recent study by Chen et al. [
          <xref ref-type="bibr" rid="ref12">12</xref>
          ] an adaptive
coumalicious applications. the authors presented new ML pled multi-level intrusion detection method combining
algorithms, i.e. rotation forest, for malware identity. Arti- whitelist technology and machine learning is presented.
ifcial Neural Network (ANN) and raw API call sequences A whitelist was used to filter communication and a
maare methods for detecting Android malware. A recent chine learning model was used to identify abnormal
comstudy by Wang et al. presented a hybrid model based munication. In this article, the adaptive PSO algorithm
on deep autoencoder (DAE) and convolutional neural and the artificial fish shoal (AFS) algorithm were used
network (CNN) to increase the accuracy and eficiency to optimize the parameters for the machine learning
of large Android malware detection [
          <xref ref-type="bibr" rid="ref9">9</xref>
          ]. model. The method was tested on the KDD’99 Cup, Gas
        </p>
        <p>
          Another research direction that attracted the attention Pipeline and industrial terrain datasets. The empirical
of scientists was the use of bio-inspired methods for mal- result showed that the proposed model is efective in
ware classification. These techniques have mainly been diferent types of attacks.
used for feature optimization and parameter optimization A clustering technique based on Fuzzified Cuckoo for
for classifiers [
          <xref ref-type="bibr" rid="ref9">9</xref>
          ]. anomaly detection is presented. The technique consists
of two phases: the detection phase and the training phase.
4.2. Intrusion Detection In the detection phase, a fuzzy deterministic approach
was used to identify anomalies based on input data and
An intrusion detection system (IDS) is a system that previously calculated distance functions. Experimental
should protect the system from possible incidents, im- results showed that the model was efective with an
acminent threats or breaches. Artificial intelligence-based curacy rate of 97.77% and a false alarm rate of 1.297%.
techniques are suitable for IDS development and outper- In the training phase, cuckoo search optimization (CSO),
form other techniques due to their flexibility, fast calcu- k-means clustering and decision tree criterion (DTC) are
lations, fast learning and adaptability. therefore, many combined to estimate the distance functions.
researchers have studied intelligent methods to improve Meanwhile, artificial bee colonies and artificial fish
the performance of IDS. focused on developing optimized swarm algorithms are included to deal with complex IDS
features and improving classifiers to reduce false alarms. problems. In this paper, a hybrid classification method
Some recent notable studies are listed as follows. based on ABC and AFS algorithms is proposed to improve
the accuracy of IDS detection. Datasets NSL-KDD and media analytics and bio-inspired computing. Specifically,
UNSV-NB15 were used to evaluate the performance of they used a modified k-means-integrated firefly flight
the method [
          <xref ref-type="bibr" rid="ref12">12</xref>
          ]. algorithm (LFA) with chaotic maps to identify spammers.
A total of 14,235 profiles were used to evaluate the
per4.3. Phishing and SPAM Detection formance of the method. The empirical result showed
that the proposed model is efective with an accuracy of
A phishing attack is a cyber attack that attempts to steal 97.98% [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ].
a user’s identity or financial credentials. Today, phishing A recent study by Faris et al. presented a spam
detecattacks are one of the most dangerous threats on the tion and identification system based on genetic algorithm
Internet. Various new approaches have been used to deal (GA) and random weight network (RVN). According to
with these problems. the experiments, the proposed system achieved
outstand
        </p>
        <p>Presented a phishing detection scheme called phish- ing results in terms of accuracy, precision and recall [15].
ing email detection system (PEDS), which joined neural
network development and assisted learning. Their model 4.4. Other: Remove APTs and Identify
achieved an accuracy rate of 98.6% and a false positive
rate of 1.8%. DGA</p>
        <p>Also introduced an anti-phishing method, which used Some existing works using AI approaches to mitigate
several diferent ML algorithms and nineteen features to other types of cyber threats are presented. More
specifdistinguish phishing websites from legitimate ones. the ically, the methods against APT attacks and DGA are
model was found to achieve a 99.39% true positive rate. described as follows.</p>
        <p>
          Another approach by Feng et al. [
          <xref ref-type="bibr" rid="ref13">13</xref>
          ], applied a neural
network to identify phishing websites by adopting the 4.4.1. Countering an Advanced, Persistent Threat
Monte Carlo algorithm and the principle of risk
minimization. Empirical results showed that their model achieved An Advanced Persistent Threat (APT) is a sophisticated
an accurate detection rate of 97.71% and a false alarm cyber attack that uses advanced techniques to exploit
rate of 1.7%. sensitive data and remain undetected. Attackers often
        </p>
        <p>
          A recent study he conducted introduced a real-time focus on valuable targets, such as agencies of large
corpoanti-phishing system that used seven diferent classifica- rations and government organizations, with the ultimate
tion algorithms and features based on natural language goal of long-term information theft. To defend against
processing (NLP). According to the authors, their ap- APT attacks, scientists have proposed various artificial
proach gave a promising result with an accuracy rate of intelligence techniques to deal with these cyber threats.
97.98% [
          <xref ref-type="bibr" rid="ref13">13</xref>
          ]. A decision tree was applied to build an IDS to detect
        </p>
        <p>
          Another study built a stacking model by combining APT attacks. It can quickly react to APTs and detect an
GBDT, KSGBoost, and LightGBM using URL and HTML intrusion early on to minimize damage. Empirical results
features to classify phishing websites. The authors re- showed that the proposed system achieved a high APT
ported that their approach achieved an accuracy rate of detection rate.
98.60% [
          <xref ref-type="bibr" rid="ref13">13</xref>
          ]. Meanwhile, Sharma et al. [16] presented a framework
        </p>
        <p>The term "SPAM" refers to unsolicited e-mail (spam). architecture for APT detection, which was based on
mulSpam can lead to inappropriate content and security tiple parallel classifiers. According to the authors, the
issues. To overcome the shortcomings of these cyber proposed framework achieved high eficiency and
accuthreats, scientists have recently applied various new, in- racy.
telligent techniques to build spam filter systems. Explored how deep neural networks (DNNs), which</p>
        <p>A spam categorization technique using modified used raw dynamic analysis features, could be used to
cuckoo search is designed to improve spam classifica- attribute APTs to a nation-state. During evaluation with
tion. cuckoo step size search was used for feature extrac- a training set containing 3200 samples, the proposed
tion and SVM for classification. The proposed approach approach reached an accuracy of 94.6% [16].
was tested on two spam datasets—Bare-ling and Lemm- Burnap et al. [17] used machine activity metrics and
ling—and obtained a competitive result. a feature map self-organizing approach to distinguish</p>
        <p>Later, the research he conducted proposed a system between legitimate and malicious software. method has
to filter spam Facebook messages using AI and machine shown promise for APT detection.
learning based technique. PSO algorithm was adopted Another approach introduced an ML-based approach
for feature selection, and SVM and decision tree for clas- called MLAPT to identify and predict APTs. According to
sification. the authors, their system had the ability to predict APT</p>
        <p>
          Recently, Aswani et al. [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ] provided a hybrid ap- attacks early. Experiments showed that MLAPT had a
proach to detect spam profiles on Twitter using social
true positive rate and a false positive rate of 81.8% and
4.5% respectively [17].
4.4.2. Identifying Domain Names Generated by
        </p>
        <p>DGA
Domain Generation Algorithms (DGA) are algorithms
used to create a huge number of pseudo-random domain
names to hide the operator’s command and control (C &amp;
C) server and avoid detection.</p>
        <p>Curtin et al. [18] also applied a similar approach using
the generalized likelihood ratio test (GLRT) and obtained
promising results.</p>
        <p>Yu et al. [19] performed a comparative analysis of
architectures based on Convolutional Neural Network
(CNN) and Recurrent Neural Networks (RNN), tested
using a dataset of one million domain names. The authors
reported that all comparative models performed well with
high accuracy rates and low false positive rates.</p>
        <p>presented a new algorithm based on long-short-term
memory (LSTM) network to solve the multi-class
imbalance problem in DGA malware detection. Based on the
obtained results, the proposed algorithm provided an
improvement over the original LSTM.</p>
        <p>In a recent study, IF-TF was used for DGA and a
machine learning-based hidden channel detection DNS
system. the proposed approach achieved an outstanding
accuracy of 99.92% [20].</p>
        <p>Another approach in proposed a framework for
identifying word-based DGAs using word frequency
distributions and an ensemble classifier constructed from naive
Bayesian, extra-tree, and logistic regression. The authors
reported that their method outperformed comparable
ones [20].</p>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>5. Conclusion</title>
      <p>The development of technology greatly facilitates our
lives in the future. Every new technology that appears
brings with it a huge number of advantages, but
unfortunately, the disadvantages are what first catches the
eye. People as people, look at everything to abuse. The
same situation is with articfiial intelligence. The area
that gives us so many advantages, is a very big problem
for the future because of its shortcomings when it comes
to privacy. Fortunately, the power of this technology is
so great that it brings with it numerous solutions. The
fact is that people are not suficiently informed about the
risk of leaving their personal information on the Internet,
regardless of the fact that no one is forcing us to do so.
It is very important that the number of people working
on data security solutions is higher than those who are
trying to abuse it because data protection is the first wall
of defense against crime of today.
tection of spammers in twitter marketing: a hybrid
approach using social media analytics and bio
inspired computing, Information Systems Frontiers
20 (2018) 515–530.
[15] H. Faris, A.-Z. Ala’M, A. A. Heidari, I. Aljarah,
M. Mafarja, M. A. Hassonah, H. Fujita, An
intelligent system for spam detection and identification
of the most relevant features based on evolutionary
random weight networks, Information Fusion 48
(2019) 67–83.
[16] P. K. Sharma, S. Y. Moon, D. Moon, J. H. Park,
Dfaad: a distributed framework architecture for the
detection of advanced persistent threats, Cluster
Computing 20 (2017) 597–609.
[17] P. Burnap, R. French, F. Turner, K. Jones, Malware
classification using self organising feature maps
and machine activity data, computers &amp; security
73 (2018) 399–410.
[18] R. R. Curtin, A. B. Gardner, S. Grzonkowski, A.
Kleymenov, A. Mosquera, Detecting dga domains with
recurrent neural networks and side information, in:
Proceedings of the 14th international conference on
availability, reliability and security, 2019, pp. 1–10.
[19] B. Yu, J. Pan, J. Hu, A. Nascimento, M. De Cock,
Character level based detection of dga domain
names, in: 2018 international joint conference on
neural networks (IJCNN), IEEE, 2018, pp. 1–8.
[20] Z. Wang, H. Dong, Y. Chi, J. Zhang, T. Yang, Q. Liu,
Dga and dns covert channel detection system based
on machine learning, in: Proceedings of the 3rd
International Conference on Computer Science and
Application Engineering, 2019, pp. 1–5.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>M.</given-names>
            <surname>Taddeo</surname>
          </string-name>
          ,
          <article-title>Three ethical challenges of applications of artificial intelligence in cybersecurity</article-title>
          ,
          <source>Minds and machines 29</source>
          (
          <year>2019</year>
          )
          <fpage>187</fpage>
          -
          <lpage>191</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>B.</given-names>
            <surname>Alhayani</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H. J.</given-names>
            <surname>Mohammed</surname>
          </string-name>
          ,
          <string-name>
            <given-names>I. Z.</given-names>
            <surname>Chaloob</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J. S.</given-names>
            <surname>Ahmed</surname>
          </string-name>
          ,
          <article-title>Efectiveness of artificial intelligence techniques against cyber security risks apply of it industry</article-title>
          ,
          <source>Materials Today: Proceedings</source>
          <volume>531</volume>
          (
          <year>2021</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>T. O.</given-names>
            <surname>Ayodele</surname>
          </string-name>
          ,
          <article-title>Types of machine learning algorithms</article-title>
          ,
          <source>New advances in machine learning 3</source>
          (
          <year>2010</year>
          )
          <fpage>19</fpage>
          -
          <lpage>48</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>S.</given-names>
            <surname>Athey</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G. W.</given-names>
            <surname>Imbens</surname>
          </string-name>
          ,
          <article-title>Machine learning methods that economists should know about</article-title>
          ,
          <source>Annual Review of Economics</source>
          <volume>11</volume>
          (
          <year>2019</year>
          )
          <fpage>685</fpage>
          -
          <lpage>725</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>L.</given-names>
            <surname>Deng</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Yu</surname>
          </string-name>
          , et al.,
          <article-title>Deep learning: methods and applications</article-title>
          ,
          <source>Foundations and trends® in signal processing 7</source>
          (
          <year>2014</year>
          )
          <fpage>197</fpage>
          -
          <lpage>387</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>X.-S.</given-names>
            <surname>Yang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Karamanoglu</surname>
          </string-name>
          ,
          <article-title>Swarm intelligence and bio-inspired computation: an overview, Swarm intelligence and bio-inspired computation (</article-title>
          <year>2013</year>
          )
          <fpage>3</fpage>
          -
          <lpage>23</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>Z.</given-names>
            <surname>Xu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Ray</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Subramanyan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Malik</surname>
          </string-name>
          ,
          <article-title>Malware detection using machine learning based analysis of virtual memory access patterns</article-title>
          , in: Design, Automation &amp; Test in Europe Conference &amp;
          <source>Exhibition (DATE)</source>
          ,
          <year>2017</year>
          , IEEE,
          <year>2017</year>
          , pp.
          <fpage>169</fpage>
          -
          <lpage>174</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>Y.</given-names>
            <surname>Ye</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Chen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Hou</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W.</given-names>
            <surname>Hardy</surname>
          </string-name>
          ,
          <string-name>
            <given-names>X.</given-names>
            <surname>Li</surname>
          </string-name>
          ,
          <article-title>Deepam: a heterogeneous deep learning framework for intelligent malware detection</article-title>
          ,
          <source>Knowledge and Information Systems</source>
          <volume>54</volume>
          (
          <year>2018</year>
          )
          <fpage>265</fpage>
          -
          <lpage>285</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>J.</given-names>
            <surname>Li</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Sun</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Q.</given-names>
            <surname>Yan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Z.</given-names>
            <surname>Li</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W.</given-names>
            <surname>Srisa-An</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Ye</surname>
          </string-name>
          ,
          <article-title>Significant permission identification for machinelearning-based android malware detection</article-title>
          ,
          <source>IEEE Transactions on Industrial Informatics</source>
          <volume>14</volume>
          (
          <year>2018</year>
          )
          <fpage>3216</fpage>
          -
          <lpage>3225</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>W. L.</given-names>
            <surname>Al-Yaseen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Z. A.</given-names>
            <surname>Othman</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. Z. A.</given-names>
            <surname>Nazri</surname>
          </string-name>
          ,
          <article-title>Multilevel hybrid support vector machine and extreme learning machine based on modified k-means for intrusion detection system</article-title>
          ,
          <source>Expert Systems with Applications</source>
          <volume>67</volume>
          (
          <year>2017</year>
          )
          <fpage>296</fpage>
          -
          <lpage>303</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>F. H.</given-names>
            <surname>Botes</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Leenen</surname>
          </string-name>
          ,
          <string-name>
            <surname>R. De La Harpe</surname>
          </string-name>
          ,
          <article-title>Ant colony induced decision trees for intrusion detection</article-title>
          ,
          <source>in: 16th European Conference on Cyber Warfare and Security</source>
          ,
          <string-name>
            <surname>ACPI</surname>
          </string-name>
          ,
          <year>2017</year>
          , pp.
          <fpage>53</fpage>
          -
          <lpage>62</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>W.</given-names>
            <surname>Chen</surname>
          </string-name>
          , T. Liu,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Tang</surname>
          </string-name>
          ,
          <string-name>
            <surname>D.</surname>
          </string-name>
          <article-title>Xu, Multi-level adaptive coupled method for industrial control networks safety based on machine learning</article-title>
          ,
          <source>Safety science 120</source>
          (
          <year>2019</year>
          )
          <fpage>268</fpage>
          -
          <lpage>275</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>F.</given-names>
            <surname>Feng</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Q.</given-names>
            <surname>Zhou</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Z.</given-names>
            <surname>Shen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>X.</given-names>
            <surname>Yang</surname>
          </string-name>
          , L. Han,
          <string-name>
            <surname>J. Wang,</surname>
          </string-name>
          <article-title>The application of a novel neural network in the detection of phishing websites</article-title>
          ,
          <source>Journal of Ambient Intelligence and Humanized Computing</source>
          (
          <year>2018</year>
          )
          <fpage>1</fpage>
          -
          <lpage>15</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>R.</given-names>
            <surname>Aswani</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. K.</given-names>
            <surname>Kar</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Vigneswara</surname>
          </string-name>
          <string-name>
            <surname>Ilavarasan</surname>
          </string-name>
          , De-
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>