A DGA domain names detection modeling method based on integrating an attention mechanism and deep neural network

被引:24
|
作者
Ren, Fangli [1 ,2 ]
Jiang, Zhengwei [1 ,2 ]
Wang, Xuren [2 ,3 ]
Liu, Jian [1 ,2 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing 100093, Peoples R China
[2] Univ Chinese Acad Sci, Beijing 100093, Peoples R China
[3] Capital Normal Univ, Coll Informat Engn, Beijing 100048, Peoples R China
关键词
Domain generation algorithm; Malware; Attention mechanism; Deep learning;
D O I
10.1186/s42400-020-00046-6
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Command and control (C2) servers are used by attackers to operate communications. To perform attacks, attackers usually employee the Domain Generation Algorithm (DGA), with which to confirm rendezvous points to their C2 servers by generating various network locations. The detection of DGA domain names is one of the important technologies for command and control communication detection. Considering the randomness of the DGA domain names, recent research in DGA detection applyed machine learning methods based on features extracting and deep learning architectures to classify domain names. However, these methods are insufficient to handle wordlist-based DGA threats, which generate domain names by randomly concatenating dictionary words according to a special set of rules. In this paper, we proposed a a deep learning framework ATT-CNN-BiLSTM for identifying and detecting DGA domains to alleviate the threat. Firstly, the Convolutional Neural Network (CNN) and bidirectional Long Short-Term Memory (BiLSTM) neural network layer was used to extract the features of the domain sequences information; secondly, the attention layer was used to allocate the corresponding weight of the extracted deep information from the domain names. Finally, the different weights of features in domain names were put into the output layer to complete the tasks of detection and classification. Our extensive experimental results demonstrate the effectiveness of the proposed model, both on regular DGA domains and DGA that hard to detect such as wordlist-based and part-wordlist-based ones. To be precise,we got a F1 score of 98.79% for the detection and macro average precision and recall of 83% for the classification task of DGA domain names.
引用
收藏
页数:13
相关论文
共 50 条
  • [41] A Deep Learning Method Based on the Attention Mechanism for Hardware Trojan Detection
    Tang, Wenjing
    Su, Jing
    He, Jiaji
    Gao, Yuchan
    ELECTRONICS, 2022, 11 (15)
  • [42] Attention deep neural network for lane marking detection
    Xiao, Degui
    Yang, Xuefeng
    Li, Jianfang
    Islam, Merabtene
    KNOWLEDGE-BASED SYSTEMS, 2020, 194
  • [43] DGA Domain Name Detection Method Based on Double Branch Feature Extraction and Adaptive Capsule Network
    Yang, Hong-Yu
    Zhang, Tao
    Zhang, Liang
    Cheng, Xiang
    Hu, Ze
    Ruan Jian Xue Bao/Journal of Software, 2024, 35 (08): : 3626 - 3646
  • [44] D3-SACNN: DGA Domain Detection With Self-Attention Convolutional Network
    Zhao, Kejun
    Guo, Wei
    Qin, Fenglin
    Wang, Xinjun
    IEEE Access, 2022, 10 : 69250 - 69263
  • [45] D3-SACNN: DGA Domain Detection With Self-Attention Convolutional Network
    Zhao, Kejun
    Guo, Wei
    Qin, Fenglin
    Wang, Xinjun
    IEEE ACCESS, 2022, 10 : 69250 - 69263
  • [46] A deep neural network based method for magnetic anomaly detection
    Wang, Yizhen
    Han, Qi
    Zhao, Guanyi
    Li, Minghui
    Zhan, Dechen
    Li, Qiong
    IET SCIENCE MEASUREMENT & TECHNOLOGY, 2022, 16 (01) : 50 - 58
  • [47] Intrusion detection method based on a deep convolutional neural network
    Zhang S.
    Xie X.
    Xu Y.
    Qinghua Daxue Xuebao/Journal of Tsinghua University, 2019, 59 (01): : 44 - 52
  • [48] Detection Method of Citrus Based on Deep Convolution Neural Network
    Bi S.
    Gao F.
    Chen J.
    Zhang L.
    Nongye Jixie Xuebao/Transactions of the Chinese Society for Agricultural Machinery, 2019, 50 (05): : 181 - 186
  • [49] Domain-Embeddings Based DGA Detection with Incremental Training Method
    Fang, Xin
    Sun, Xiaoqing
    Yang, Jiahai
    Liu, Xinran
    2020 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (ISCC), 2020, : 185 - 190
  • [50] Efficient Lane Detection Technique Based on Lightweight Attention Deep Neural Network
    Yao, Zhiting
    Chen, Xiyuan
    Journal of Advanced Transportation, 2022, 2022