期刊文献+

融合注意力机制与并行混合网络的DGA域名检测

DGA Domain Name Detection Combining Attention Mechanisms and Parallel Hybrid Network
下载PDF
导出
摘要 基于统计特征的DGA域名检测方法依赖复杂的特征工程,而现有端到端的深度学习方法在DGA域名家族的多分类任务中性能表现不佳。针对上述问题,提出一种融合注意力机制与并行混合网络的DGA域名检测方法。首先,引入深层金字塔卷积神经网络,提取域名深层语义信息,并使用通道注意力块SENet进行改进构建DPCNN-SE,自适应学习通道间关系,抑制无用特征的传递;同时,将自注意力机制与双向长短时记忆网络结合构建Bi LSTM-SA网络,捕获域名数据中最具代表性的全局时序特征;最后,融合2个网络提取的特征,输入softmax层输出分类结果。实验结果表明,该方法在域名家族的多分类任务中相比CNN、LSTM的单一模型,F1值分别提高了10.30个百分点、10.18个百分点;相较于现有的混合网络方法 Bilbo和Bi GRU-MCNN,F1值分别提高了5.97个百分点、4.87个百分点,并且具有更低的计算复杂度。 Statistical feature-based DGA domain name detection methods relies on complex feature engineering,while the existing end-to-end deep learning methods perform poorly in the multi-classification tasks. To address these problems,a DGA domain name detection method combining attention mechanisms and parallel hybrid networks is proposed. Firstly,deep pyramid convolutional neural networks is introduced to extract deep semantic information of domain names,and DPCNN-SE is proposed by improving DPCNN using the channel attention block called SENet,which can learn inter-channel relationships adaptively and suppress the transmission of useless features. Meanwhile,the self-attention mechanism and the bidirectional long short-term memory network are combined to construct the Bi LSTM-SA network to capture the most representative global temporal features in domain name data. Finally,the features extracted by the two networks are fused and fed into the softmax layer to output the classification results. The experimental results show that the method increases the F1-score by 10. 30 percentage points and 10. 18 percentage points in the multi-classification task of domain name family compared with the single model of CNN and LSTM,respectively;the F1-score increases by 5. 97 percentage points and 4. 87 percentage points,respectively,compared with the existing hybrid model method Bilbo and Bi GRU-MCNN,and has lower computational complexity.
作者 刘立婷 欧毓毅 LIU Li-ting;OU Yu-yi(School of Computers,Guangdong University of Technology,Guangzhou 510006,China)
出处 《计算机与现代化》 2022年第9期119-126,共8页 Computer and Modernization
基金 广州市科技计划项目(201902020007,202007010004)。
关键词 DGA域名检测 特征融合 端到端 长短记忆神经网络 卷积神经网络 DGA domain name detection feature fusion end-to-end long short-term memory neural network convolutional neural network
  • 相关文献

参考文献6

二级参考文献110

  • 1Mahmoud K, Youssef I, Andrew J. Phishing detection: A literature survey. IEEE Communications Surveys & Tutorials, 2013, 15(4): 2091-2121.
  • 2Paul K, Georgia K, Hector G M. Fighting spam on social Web sites a survey of approaches and future challenges. IEEE Internet Computing, 2007, 11(6): 36-45.
  • 3Priya M, Sandhya L, Ciza T. A static approach to detect drive-by-download attacks on Webpages//Proceedings of the International Conference on Control Communication and Computing. Xi'an, China, 2013:298-303.
  • 4Mavrommatis N P P, Monrose M A R F. All your iframes point to us//Proceedings of the 17th USENIX Security Symposium. San Jose, USA, 2008:1-22.
  • 5Ma J, Saul L K, Savage S, Voetker G M. Beyond blacklists: Learning to detect malicious Web sites from suspicious URLs//Proceedings of the 15th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining. New York, USA, 2009: 1245-1253.
  • 6Ma J, Saul L K, Savage S, Voelker G M. Identifying suspi- cious URLs: An application of large-scale online learning// Proceedings of the 26th Annual International Conference on Machine Learning. Montreal, Canada, 2009:681-688.
  • 7Ma J, Saul L K, Savage S, Voelker G M. Learning to detect malicious URLs. ACM Transactions on Intelligent Systems and Technology, 2011, 2(3): 1-24.
  • 8Canali D, et al. Prophiler: A fast filter for the large-scale detection of malicious Web pages//Proceedings of the 20th International Conference on World Wide Web. Hyderabad, India, 2011:197-206.
  • 9Thomas K, et al. Design and evaluation of a real-time URL spam filtering service//Proceedings of the IEEE Symposium on Security and Privacy. Oakland, USA, 2011:447-462.
  • 10Yadav S, Reddy A K K, Reddy A L, et al. Detecting algorithmic.ally generated malicious domain names//Proeeedings of the 10th ACM SIGCOMM Conference on Internet Measurement. New York, USA, 2010:48-61.

共引文献106

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部