A DGA domain names detection modeling method based on integrating an attention mechanism and deep neural network

被引:24
|
作者
Ren, Fangli [1 ,2 ]
Jiang, Zhengwei [1 ,2 ]
Wang, Xuren [2 ,3 ]
Liu, Jian [1 ,2 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing 100093, Peoples R China
[2] Univ Chinese Acad Sci, Beijing 100093, Peoples R China
[3] Capital Normal Univ, Coll Informat Engn, Beijing 100048, Peoples R China
关键词
Domain generation algorithm; Malware; Attention mechanism; Deep learning;
D O I
10.1186/s42400-020-00046-6
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Command and control (C2) servers are used by attackers to operate communications. To perform attacks, attackers usually employee the Domain Generation Algorithm (DGA), with which to confirm rendezvous points to their C2 servers by generating various network locations. The detection of DGA domain names is one of the important technologies for command and control communication detection. Considering the randomness of the DGA domain names, recent research in DGA detection applyed machine learning methods based on features extracting and deep learning architectures to classify domain names. However, these methods are insufficient to handle wordlist-based DGA threats, which generate domain names by randomly concatenating dictionary words according to a special set of rules. In this paper, we proposed a a deep learning framework ATT-CNN-BiLSTM for identifying and detecting DGA domains to alleviate the threat. Firstly, the Convolutional Neural Network (CNN) and bidirectional Long Short-Term Memory (BiLSTM) neural network layer was used to extract the features of the domain sequences information; secondly, the attention layer was used to allocate the corresponding weight of the extracted deep information from the domain names. Finally, the different weights of features in domain names were put into the output layer to complete the tasks of detection and classification. Our extensive experimental results demonstrate the effectiveness of the proposed model, both on regular DGA domains and DGA that hard to detect such as wordlist-based and part-wordlist-based ones. To be precise,we got a F1 score of 98.79% for the detection and macro average precision and recall of 83% for the classification task of DGA domain names.
引用
收藏
页数:13
相关论文
共 50 条
  • [31] Vulnerability Detection Based on Deep Graph Convolutional Network and Attention Mechanism
    Xiao, Peng
    Zhang, Xusheng
    Yang, Fengyu
    Zheng, Wei
    Computer Engineering and Applications, 1600, 3 (292-305):
  • [32] Rumor detection based on propagation graph neural network with attention mechanism
    Wu, Zhiyuan
    Pi, Dechang
    Chen, Junfu
    Xie, Meng
    Cao, Jianjun
    EXPERT SYSTEMS WITH APPLICATIONS, 2020, 158
  • [33] Intelligent crack detection based on attention mechanism in convolution neural network
    Cui, Xiaoning
    Wang, Qicai
    Dai, Jinpeng
    Xue, Yanjin
    Duan, Yun
    ADVANCES IN STRUCTURAL ENGINEERING, 2021, 24 (09) : 1859 - 1868
  • [34] Qualitative Modeling Method of Mango Species in Near Infrared Based on Attention Mechanism Residual Neural Network
    Wang Shu-tao
    Wan Jin-cong
    Liu Shi-yu
    Zhang Jin-qing
    Wang Yu-tian
    SPECTROSCOPY AND SPECTRAL ANALYSIS, 2024, 44 (08) : 2262 - 2267
  • [35] Integrating articulatory data in deep neural network-based acoustic modeling
    Badino, Leonardo
    Canevari, Claudia
    Fadiga, Luciano
    Metta, Giorgio
    COMPUTER SPEECH AND LANGUAGE, 2016, 36 : 173 - 195
  • [36] A Depression Diagnosis Method Based on the Hybrid Neural Network and Attention Mechanism
    Wang, Zhuozheng
    Ma, Zhuo
    Liu, Wei
    An, Zhefeng
    Huang, Fubiao
    BRAIN SCIENCES, 2022, 12 (07)
  • [37] Improved Music Recommendation Algorithm for Deep Neural Network Based on Attention Mechanism
    He, Xin
    MOBILE INFORMATION SYSTEMS, 2022, 2022
  • [38] Image super -resolution based on deep neural network of multiple attention mechanism *
    Yang, Xin
    Li, Xiaochuan
    Li, Zhiqiang
    Zhou, Dake
    JOURNAL OF VISUAL COMMUNICATION AND IMAGE REPRESENTATION, 2021, 75
  • [39] DSQNet: Domain SeQuence based Deep Neural Network for AGDs Detection
    Xiong, Wei
    Jiang, Haiyang
    Guan, Hongtao
    Liu, Fengrui
    26TH IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (IEEE ISCC 2021), 2021,
  • [40] Efficient detection method for young apples based on the fusion of convolutional neural network and visual attention mechanism
    Song H.
    Jiang M.
    Wang Y.
    Song L.
    Nongye Gongcheng Xuebao/Transactions of the Chinese Society of Agricultural Engineering, 2021, 37 (09): : 297 - 303