A DGA domain names detection modeling method based on integrating an attention mechanism and deep neural network

被引:24
|
作者
Ren, Fangli [1 ,2 ]
Jiang, Zhengwei [1 ,2 ]
Wang, Xuren [2 ,3 ]
Liu, Jian [1 ,2 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing 100093, Peoples R China
[2] Univ Chinese Acad Sci, Beijing 100093, Peoples R China
[3] Capital Normal Univ, Coll Informat Engn, Beijing 100048, Peoples R China
关键词
Domain generation algorithm; Malware; Attention mechanism; Deep learning;
D O I
10.1186/s42400-020-00046-6
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Command and control (C2) servers are used by attackers to operate communications. To perform attacks, attackers usually employee the Domain Generation Algorithm (DGA), with which to confirm rendezvous points to their C2 servers by generating various network locations. The detection of DGA domain names is one of the important technologies for command and control communication detection. Considering the randomness of the DGA domain names, recent research in DGA detection applyed machine learning methods based on features extracting and deep learning architectures to classify domain names. However, these methods are insufficient to handle wordlist-based DGA threats, which generate domain names by randomly concatenating dictionary words according to a special set of rules. In this paper, we proposed a a deep learning framework ATT-CNN-BiLSTM for identifying and detecting DGA domains to alleviate the threat. Firstly, the Convolutional Neural Network (CNN) and bidirectional Long Short-Term Memory (BiLSTM) neural network layer was used to extract the features of the domain sequences information; secondly, the attention layer was used to allocate the corresponding weight of the extracted deep information from the domain names. Finally, the different weights of features in domain names were put into the output layer to complete the tasks of detection and classification. Our extensive experimental results demonstrate the effectiveness of the proposed model, both on regular DGA domains and DGA that hard to detect such as wordlist-based and part-wordlist-based ones. To be precise,we got a F1 score of 98.79% for the detection and macro average precision and recall of 83% for the classification task of DGA domain names.
引用
收藏
页数:13
相关论文
共 50 条
  • [1] A DGA domain names detection modeling method based on integrating an attention mechanism and deep neural network
    Fangli Ren
    Zhengwei Jiang
    Xuren Wang
    Jian Liu
    Cybersecurity, 3
  • [2] Integrating an Attention Mechanism and Deep Neural Network for Detection of DGA Domain Names
    Ren, Fangli
    Jiang, Zhengwei
    Liu, Jian
    2019 IEEE 31ST INTERNATIONAL CONFERENCE ON TOOLS WITH ARTIFICIAL INTELLIGENCE (ICTAI 2019), 2019, : 848 - 855
  • [3] Detection method of domain names generated by DGAs based on semantic representation and deep neural network
    Xu, Congyuan
    Shen, Jizhong
    Du, Xin
    COMPUTERS & SECURITY, 2019, 85 : 77 - 88
  • [4] Character Level based Detection of DGA Domain Names
    Yu, Bin
    Pan, Jie
    Hu, Jiaming
    Nascimento, Anderson
    De Cock, Martine
    2018 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2018,
  • [5] DOLPHIN: Phonics based Detection of DGA Domain Names
    Zhao, Dan
    Li, Hao
    Sun, Xiuwen
    Tang, Yazhe
    2021 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2021,
  • [6] Hierarchical neural network detection model based on deep context and attention mechanism
    Zhang, Yuxi
    Zhao, Yu
    INTERNATIONAL JOURNAL OF COMPUTING SCIENCE AND MATHEMATICS, 2023, 18 (02) : 162 - 175
  • [7] A hybrid DGA DefenseNet for detecting DGA domain names based on FastText and deep learning techniques
    Chen, Jiann-Liang
    Qiu, Jian-Fu
    Chen, Yu-Hung
    COMPUTERS & SECURITY, 2025, 150
  • [8] A DGA Domain Name Detection Model Based on A Hybrid Deep Neural Network with Multi-dimensional Features
    Pan, Rui
    Wang, Yu
    Wang, Zuchao
    IAENG International Journal of Computer Science, 2025, 52 (01) : 11 - 22
  • [9] Detection for domain generation algorithm (DGA) domain botnet based on neural network with multi-head self-attention mechanisms
    Sarojini, S.
    Asha, S.
    INTERNATIONAL JOURNAL OF SYSTEM ASSURANCE ENGINEERING AND MANAGEMENT, 2022,
  • [10] Novel Botnet DGA Domain Detection Method Based on Character Level Sliding Window and Deep Residual Network
    Liu, Xiao-Yang
    Liu, Jia-Miao
    Liu, Chao
    Zhang, Yi-Hao
    Tien Tzu Hsueh Pao/Acta Electronica Sinica, 2022, 50 (01): : 250 - 256