Domain Generation Algorithm (DGA)
Definition
Code embedded in malware that produces a large set of pseudo-random domain names on a scheduled basis. The malware tries each until one resolves, connecting it to command-and-control infrastructure even if most of the domain list has been blocked.
- Embedded in
- Malware
- Function
- Generates pseudo-random domain names
- Purpose
- Reach command-and-control infrastructure
- Resilience
- Survives partial domain blocklisting
Common questions
Why do defenders find DGA traffic useful as a detection signal?+
The generated domains are typically long, high-entropy strings unlike normal browsing traffic, and DNS resolution attempts for many such domains in a short window from one host is itself a strong indicator of compromise even before any domain resolves successfully.
Why can't defenders simply block all DGA domains in advance?+
The algorithm can produce thousands of candidate domains per day and the attacker registers only a small, often rotating subset, so blocklisting is a losing race. Defenders instead focus on detecting the query pattern or reverse-engineering the algorithm to predict future domains.
Related terms
- A Record
- A DNS resource record that maps a domain name to an IPv4 address. The primary attribution record in most investigations. An AAAA...
- DNS Tunnelling
- Encoding data inside DNS queries and responses to exfiltrate information or carry command-and-control traffic through a network that permits DNS but blocks...
- Fast-Flux
- An evasion technique in which a domain's A records cycle through a large pool of IP addresses with very short TTL values....
- Indicator of Compromise (IoC)
- An observable artefact that suggests a system has been involved in a malicious event. Static analysis produces file-based IoCs: cryptographic hashes, embedded...
- MISP (Malware Information Sharing Platform)
- An open-source threat intelligence platform that enables structured sharing of IOCs and threat intelligence using STIX and other formats. Widely deployed by...
- Passive DNS
- A historical database of DNS resolutions collected by sensors at recursive resolvers or network taps. Passive DNS shows which IP addresses a...
- Pyramid of Pain
- A model proposed by David Bianco that ranks IOC types by the cost to an attacker of changing them when defenders start...
- STIX (Structured Threat Information eXpression)
- An OASIS open standard that defines a JSON-based language for describing cyber threat intelligence. STIX 2.1 defines objects for indicators, threat actors,...
- TAXII (Trusted Automated eXchange of Intelligence Information)
- The transport protocol companion to STIX. TAXII defines how STIX data is exchanged between servers and clients over HTTPS, enabling automated ingestion...
- WHOIS
- A query protocol that returns registration data for a domain, including registrant name, organisation, email, nameservers, and registration and expiry dates. Since...
Explained in these topics
- DNS and Domain Investigation
- Indicators of Compromise: Identification and UseA technique used by malware to generate large numbers of candidate command-and-control domain names algorithmically, making it impractical to block the attacke...