An Improved CNN-LSTM Algorithm for Detection of DGA Domain Name

被引:0
|
作者
Qi, Guorong [1 ]
Mao, Jian [1 ]
机构
[1] Jimei Univ, Coll Comp Engn, Xiamen 361021, Peoples R China
关键词
domain name generation algorithm; dictionary based domain name generation algorithm; convolutional neural network; long-term and short-term memory network; domain name detection;
D O I
10.1145/3650400.3650618
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recently, zombie networks have utilized domain name generation algorithm (DGA) to generate a large number of malicious domain names for network attacks, posing a threat to network security. The existing DGA domain names are mainly divided into dictionary type and character type. However, traditional deep learning methods cannot simultaneously detect two types of DGA domain names, especially dictionary based DGA domain names. Therefore, this study proposes a network model that combines convolutional neural networks (CNN) and long-short term memory (LSTM) networks - the CNN-LSTM model. The model consists of three parts: character embedding layer, feature extraction layer, and fully connected layer. This model can extract N-grams features of domain name characters through CNN and input the extraction results to LSTM. At the same time, the model can choose to use multiple sets of CNN in combination with LSTM. In addition, based on the extracted features, this model can classify and predict domain names generated by dictionary based DGA. The experimental results show that the proposed model performs best when the convolutional kernel sizes selected by CNN are 3 and 4. In the comparative experiments of four dictionary based DGA families, the CNN-LSTM model showed a 3.0% improvement in accuracy compared to the CNN model, and as the number of sample families increased, the CNN-LSTM model exhibited better stability.
引用
下载
收藏
页码:1293 / 1298
页数:6
相关论文
共 50 条
  • [1] An Intelligent Algorithm Based on the Improved CNN-LSTM for the Detection of Concrete Reinforcement Information
    School of Control Science and Engineering, Tiangong University, Tianjin
    300387, China
    不详
    300387, China
    不详
    Prog. Electromagn. Res. M, 2024, (49-61):
  • [2] BotDetector: a system for identifying DGA-based botnet with CNN-LSTM
    Zang, Xiaodong
    Cao, Jianbo
    Zhang, Xinchang
    Gong, Jian
    Li, Guiqing
    TELECOMMUNICATION SYSTEMS, 2024, 85 (02) : 207 - 223
  • [3] BotDetector: a system for identifying DGA-based botnet with CNN-LSTM
    Xiaodong Zang
    Jianbo Cao
    Xinchang Zhang
    Jian Gong
    Guiqing Li
    Telecommunication Systems, 2024, 85 : 207 - 223
  • [4] Malicious Domain Name Detection Model Based on CNN and LSTM
    Zhang Bin
    Liao Renjie
    JOURNAL OF ELECTRONICS & INFORMATION TECHNOLOGY, 2021, 43 (10) : 2944 - 2951
  • [5] An improved capuchin search algorithm optimized hybrid CNN-LSTM architecture for malignant lung nodule detection
    Kanipriya, M.
    Hemalatha, C.
    Sridevi, N.
    SriVidhya, S. R.
    Shabu, S. L. Jany
    BIOMEDICAL SIGNAL PROCESSING AND CONTROL, 2022, 78
  • [6] An improved capuchin search algorithm optimized hybrid CNN-LSTM architecture for malignant lung nodule detection
    Kanipriya, M.
    Hemalatha, C.
    Sridevi, N.
    SriVidhya, S.R.
    Jany Shabu, S.L.
    Biomedical Signal Processing and Control, 2022, 78
  • [7] CNN-LSTM based Approach for DDoS Detection
    Alasmari, Tahani
    Eshmawi, Ala'
    Alshomrani, Adel
    Hsairi, Lobna
    2023 EIGHTH INTERNATIONAL CONFERENCE ON MOBILE AND SECURE SERVICES, MOBISECSERV, 2023,
  • [8] Fault Detection of the Harmonic Reducer Based on CNN-LSTM With a Novel Denoising Algorithm
    Zhi, Zhuo
    Liu, Liansheng
    Liu, Datong
    Hu, Cong
    IEEE SENSORS JOURNAL, 2022, 22 (03) : 2572 - 2581
  • [9] 基于改进的CNN-LSTM的DGA域名检测算法
    褚冰融
    付海艳
    刘梦
    海南师范大学学报(自然科学版), 2023, 36 (03) : 237 - 248
  • [10] An efficient CNN-LSTM model for sentiment detection in #BlackLivesMatter
    Ankita
    Rani, Shalli
    Bashir, Ali Kashif
    Alhudhaif, Adi
    Koundal, Deepika
    Gunduz, Emine Selda
    EXPERT SYSTEMS WITH APPLICATIONS, 2022, 193