HANDOM: Heterogeneous Attention Network Model for Malicious Domain Detection

被引:4
|
作者
Wang, Qing [1 ,2 ]
Dong, Cong [3 ]
Jian, Shijie [4 ]
Du, Dan [1 ,2 ]
Lu, Zhigang [1 ,2 ]
Qi, Yinhao [1 ,2 ]
Han, Dongxu [1 ,2 ]
Ma, Xiaobo [5 ]
Wang, Fei [6 ]
Liu, Yuling [1 ,2 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing, Peoples R China
[2] Univ Chinese Acad Sci, Sch Cyber Secur, Beijing, Peoples R China
[3] Zhongguancun Lab, Beijing, Peoples R China
[4] Minist Publ Secur, Res Inst 1, Beijing, Peoples R China
[5] Xi An Jiao Tong Univ, Sch Comp Sci & Technol, Xian, Peoples R China
[6] Chinese Acad Sci, Inst Comp Technol, Beijing, Peoples R China
关键词
Malware domain detection; Spatial -Temporal contextual correlation; Heterogeneous attention network; Statistical -and -Structural information; DNS;
D O I
10.1016/j.cose.2022.103059
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Malicious domains are crucial vectors for attackers to conduct malicious activities. With the increasing numbers in domain-based attack activities and the enhancement of attacker evasion methods, the de-tection of malicious domains has become critical and increasingly difficult. Statistical feature-based and graph structure-based detection methods are mainstream technical approaches. However, highly hidden domains can escape feature detection, and the detection range of graph structure-based methods is lim-ited. Based on these, we propose a malicious detection method called HANDOM. HANDOM combines statistical features and graph structural information to neutralize their limitations, and uses the Hetero-geneous Attention Network (HAN) model to jointly handle both information to achieve high-performance malicious domain classification. We conduct experimental evaluations on real-world datasets and com-pare HANDOM with machine learning methods and other malicious detection methods. The results present that HANDOM has superior and robust performance, and can identify highly hidden domains.(c) 2022 Elsevier Ltd. All rights reserved.
引用
收藏
页数:14
相关论文
共 50 条
  • [1] Heterogeneous Graph Attention Network for Malicious Domain Detection
    Li, Zhiping
    Yuan, Fangfang
    Liu, Yanbing
    Cao, Cong
    Fang, Fang
    Tan, Jianlong
    ARTIFICIAL NEURAL NETWORKS AND MACHINE LEARNING - ICANN 2022, PT II, 2022, 13530 : 506 - 518
  • [2] Malicious Domain Detection with Heterogeneous Graph Propagation Network
    Hu, Cheng
    Yuan, Fangfang
    Liu, Yanbing
    Cao, Cong
    Zhang, Chunyan
    Tan, Jianlong
    WIRELESS ALGORITHMS, SYSTEMS, AND APPLICATIONS (WASA 2022), PT I, 2022, 13471 : 545 - 556
  • [3] Attributed Heterogeneous Graph Neural Network for Malicious Domain Detection
    Zhang, Shuai
    Zhou, Zhou
    Li, Da
    Zhong, Youbing
    Liu, Qingyun
    Yang, Wei
    Li, Shu
    PROCEEDINGS OF THE 2021 IEEE 24TH INTERNATIONAL CONFERENCE ON COMPUTER SUPPORTED COOPERATIVE WORK IN DESIGN (CSCWD), 2021, : 397 - 403
  • [4] Malicious Blockchain Domain Detection Based on Heterogeneous Information Network
    Han, Jian
    Wang, Zhonghua
    Jiang, Songhao
    Zang, Tianning
    2022 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM 2022), 2022, : 2597 - 2602
  • [5] Malicious Domain Name Detection Model Based on CNN-GRU-Attention
    Jiang, Yanshu
    Jia, Mingqi
    Zhang, Biao
    Deng, Liwei
    PROCEEDINGS OF THE 33RD CHINESE CONTROL AND DECISION CONFERENCE (CCDC 2021), 2021, : 1602 - 1607
  • [6] HinDom: A Robust Malicious Domain Detection System based on Heterogeneous Information Network with Transductive Classification
    Sun, Xiaoqing
    Tong, Mingkai
    Yang, Jiahai
    Liu, Xinran
    Liu, Heng
    PROCEEDINGS OF THE 22ND INTERNATIONAL SYMPOSIUM ON RESEARCH IN ATTACKS, INTRUSIONS AND DEFENSES, 2019, : 399 - 412
  • [7] Malicious code detection based on heterogeneous information network
    Liu Y.
    Hou Y.
    Yan H.
    Beijing Hangkong Hangtian Daxue Xuebao/Journal of Beijing University of Aeronautics and Astronautics, 2022, 48 (02): : 258 - 265
  • [8] HGDom: Heterogeneous Graph Convolutional Networks for Malicious Domain Detection
    Sun, Xiaoqing
    Yang, Jiahai
    Wang, Zhiliang
    Liu, Heng
    NOMS 2020 - PROCEEDINGS OF THE 2020 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM 2020: MANAGEMENT IN THE AGE OF SOFTWARIZATION AND ARTIFICIAL INTELLIGENCE, 2020,
  • [9] Deepdom: Malicious domain detection with scalable and heterogeneous graph convolutional networks
    Sun, Xiaoqing
    Wang, Zhiliang
    Yang, Jiahai
    Liu, Xinran
    COMPUTERS & SECURITY, 2020, 99
  • [10] Robust Malicious Domain Detection
    Hason, Nitay
    Dvir, Amit
    Hajaj, Chen
    CYBER SECURITY CRYPTOGRAPHY AND MACHINE LEARNING (CSCML 2020), 2020, 12161 : 45 - 61