,A DGA domain names detection modeling method based on integrating an attention mechanism and deep n

来源 :网络空间安全科学与技术(英文版) | 被引量 : 0次 | 上传用户:lyaaaaaa
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
Command and control (C2) servers are used by attackers to operate communications.To perform attacks,attackers usually employee the Domain Generation Algorithm (DGA),with which to confirm rendezvous points to their C2 servers by generating various network locations.The detection of DGA domain names is one of the important technologies for command and control communication detection.Considering the randomness of the DGA domain names,recent research in DGA detection applyed machine leaing methods based on features extracting and deep leaming architectures to classify domain names.However,these methods are insufficient to handle wordlist-based DGA threats,which generate domain names by randomly concatenating dictionary words according to a special set of rules.In this paper,we proposed a a deep leaing framework ATT-CNN-BiLSTM for identifying and detecting DGA domains to alleviate the threat.Firstly,the Convolutional Neural Network (CNN) and bidirectional Long Short-Term Memory (BiLSTM) neural network layer was used to extract the features of the domain sequences information;secondly,the attention layer was used to allocate the corresponding weight of the extracted deep information from the domain names.Finally,the different weights of features in domain names were put into the output layer to complete the tasks of detection and classification.Our extensive experimental results demonstrate the effectiveness of the proposed model,both on regular DGA domains and DGA that hard to detect such as wordlist-based and part-wordlist-based ones.To be precise,we got a F1 score of 98.79% for the detection and macro average precision and recall of 83% for the classification task of DGA domain names.
其他文献
问题意识在公文写作中的作用是多方面的.它有利于写作者深入基层调查研究;有利于写作者端正文风,倡导“短实精”文章写作;有利于激活写作者的写作思维,使文章思路畅通.问题意
Forest disasters mainly refer to insect pest, rodent damage, forest fire and frost damage. Snow damage, windstorm, drought, flooding, landslide, mud-rock flow,
信用风险一直是商业银行所面临的最基础最主要的风险,其范围涉及贷款发放、债券投资、表外业务等领域,而发放贷款一直是银行最主要的业务活动,因此,信贷风险成为信用风险中最
“三农”问题是我国经济和社会发展中的一大难题,其中又以农民增收最难解决。目前看来,调整农业结构,推行规模经营,降低成本,发展高效农业不失为提高农业效益的一种有效途径。同时
Data security and privacy issues are magnified by the volume,the variety,and the velocity of Big Data and by the lack,up to now,of a reference data model and re
新年一过,一线城市房地产市场仿佛打了兴奋剂,进入高烧模式。层出不穷的刺激政策也必将持续影响房地产市场。中国人民银行决定,自2016年3月1日起,普遍下调金融机构人民币存款准备金率0.5个百分点。对于购房者来说,降准以后银行后续资金将更加宽裕,房贷有望继续宽松,购房者压力持续降低。  开年以来,在首付比例下降、税费下调等连续不断的楼市刺激政策推动下,一二线城市楼市异常火爆,而亟需去库存的三四线城市仍
Although using machine learning techniques to solve computer security challenges is not a new idea,the rapidly emerging Deep Learning technology has recently tr
交通基础设施作为区域经济发展的基本条件,是社会经济赖以发展的重要基础设施。随着社会经济的发展,交通基础设施的建设,缩小了资源流通的时空距离,扩大了社会经济活动的范围
目前,全国共青团的各级青年报刊已经发展到五十家,仅省一级的青年报刊就有三十七家,每期的发行总量在二千万份以上。这是一支重要的队伍。共青团的青年报刊既是党的喉舌又是
西部大开发是党和国家在世纪之交做出的一项重大战略决策。西部大开发战略所指的西部地区区域范围界定为12个省、区、市,即西北五省、区,西南五省、区、市,广西壮族自治区和