PUMD: a PU learning-based malicious domain detection framework

被引:0
|
作者
Zhaoshan Fan
Qing Wang
Haoran Jiao
Junrong Liu
Zelin Cui
Song Liu
Yuling Liu
机构
[1] Chinese Academy of Sciences,Institute of Information Engineering
[2] University of Chinese Academy of Sciences,School of Cyber Security
来源
关键词
Malicious domain detection; Insufficient credible label information; Class imbalance; Incompact distribution; PU learning;
D O I
暂无
中图分类号
学科分类号
摘要
Domain name system (DNS), as one of the most critical internet infrastructure, has been abused by various cyber attacks. Current malicious domain detection capabilities are limited by insufficient credible label information, severe class imbalance, and incompact distribution of domain samples in different malicious activities. This paper proposes a malicious domain detection framework named PUMD, which innovatively introduces Positive and Unlabeled (PU) learning solution to solve the problem of insufficient label information, adopts customized sample weight to improve the impact of class imbalance, and effectively constructs evidence features based on resource overlapping to reduce the intra-class distance of malicious samples. Besides, a feature selection strategy based on permutation importance and binning is proposed to screen the most informative detection features. Finally, we conduct experiments on the open source real DNS traffic dataset provided by QI-ANXIN Technology Group to evaluate the PUMD framework’s ability to capture potential command and control (C&C) domains for malicious activities. The experimental results prove that PUMD can achieve the best detection performance under different label frequencies and class imbalance ratios.
引用
收藏
相关论文
共 50 条
  • [41] Malicious Domain Detection Based on Decision Tree
    Thein, Thin Tharaphe
    Shiraishi, Yoshiaki
    Morii, Masakatu
    IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2023, E106D (09) : 1490 - 1494
  • [42] Deepsquatting: Learning-Based Typosquatting Detection at Deeper Domain Levels
    Piredda, Paolo
    Ariu, Davide
    Biggio, Battista
    Corona, Igino
    Piras, Luca
    Giacinto, Giorgio
    Roli, Fabio
    AI*IA 2017 ADVANCES IN ARTIFICIAL INTELLIGENCE, 2017, 10640 : 347 - 358
  • [43] Deep learning-based framework for tumour detection and semantic segmentation
    Kot, Estera
    Krawczyk, Zuzanna
    Siwek, Krzysztof
    Krolicki, Leszek
    Czwarnowski, Piotr
    BULLETIN OF THE POLISH ACADEMY OF SCIENCES-TECHNICAL SCIENCES, 2021, 69 (03)
  • [44] A Deep Learning-Based Framework for Damage Detection With Time Series
    Yang, Qun
    Shen, Dejian
    Du, Wencai
    Li, Weijun
    IEEE ACCESS, 2021, 9 : 66570 - 66586
  • [45] Machine learning-based framework for saliency detection in distorted images
    Niu, Yuzhen
    Lin, Lening
    Chen, Yuzhong
    Ke, Lingling
    MULTIMEDIA TOOLS AND APPLICATIONS, 2017, 76 (24) : 26329 - 26353
  • [46] A Deep Learning-based Framework for Vehicle License Plate Detection
    Yang, Deming
    Yang, Ling
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2024, 15 (01) : 1009 - 1018
  • [47] Machine learning-based framework for saliency detection in distorted images
    Yuzhen Niu
    Lening Lin
    Yuzhong Chen
    Lingling Ke
    Multimedia Tools and Applications, 2017, 76 : 26329 - 26353
  • [48] A Deep Learning-Based DDoS Detection Framework for Internet of Things
    Ma, Li
    Chai, Ying
    Cui, Lei
    Ma, Dongchao
    Fu, Yingxun
    Xiao, Ailing
    ICC 2020 - 2020 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2020,
  • [49] A lightweight deep learning-based android malware detection framework
    Ma, Runze
    Yin, Shangnan
    Feng, Xia
    Zhu, Huijuan
    Sheng, Victor S.
    EXPERT SYSTEMS WITH APPLICATIONS, 2024, 255
  • [50] A learning-based hybrid framework for detection and defence of DDoS attacks
    Subbulakshmi T.
    Subbulakshmi, T. (research.subbulakshmi@gmail.com), 2017, Inderscience Enterprises Ltd., 29, route de Pre-Bois, Case Postale 856, CH-1215 Geneva 15, CH-1215, Switzerland (10) : 51 - 60