An Improved CNN-LSTM Algorithm for Detection of DGA Domain Name

被引:0
|
作者
Qi, Guorong [1 ]
Mao, Jian [1 ]
机构
[1] Jimei Univ, Coll Comp Engn, Xiamen 361021, Peoples R China
关键词
domain name generation algorithm; dictionary based domain name generation algorithm; convolutional neural network; long-term and short-term memory network; domain name detection;
D O I
10.1145/3650400.3650618
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recently, zombie networks have utilized domain name generation algorithm (DGA) to generate a large number of malicious domain names for network attacks, posing a threat to network security. The existing DGA domain names are mainly divided into dictionary type and character type. However, traditional deep learning methods cannot simultaneously detect two types of DGA domain names, especially dictionary based DGA domain names. Therefore, this study proposes a network model that combines convolutional neural networks (CNN) and long-short term memory (LSTM) networks - the CNN-LSTM model. The model consists of three parts: character embedding layer, feature extraction layer, and fully connected layer. This model can extract N-grams features of domain name characters through CNN and input the extraction results to LSTM. At the same time, the model can choose to use multiple sets of CNN in combination with LSTM. In addition, based on the extracted features, this model can classify and predict domain names generated by dictionary based DGA. The experimental results show that the proposed model performs best when the convolutional kernel sizes selected by CNN are 3 and 4. In the comparative experiments of four dictionary based DGA families, the CNN-LSTM model showed a 3.0% improvement in accuracy compared to the CNN model, and as the number of sample families increased, the CNN-LSTM model exhibited better stability.
引用
收藏
页码:1293 / 1298
页数:6
相关论文
共 50 条
  • [31] A Fault Diagnosis Algorithm for the Dedicated Equipment Based on the CNN-LSTM Mechanism
    Guo, Zhannan
    Hao, Yinlin
    Shi, Hanwen
    Wu, Zhenyu
    Wu, Yuhu
    Sun, Ximing
    ENERGIES, 2023, 16 (13)
  • [32] An Improved Capsule Network for DGA Domain Detection
    Yang, Hongyu
    Zhang, Tao
    Hu, Ze
    Zhang, Liang
    Cheng, Xiang
    2023 19TH INTERNATIONAL CONFERENCE ON MOBILITY, SENSING AND NETWORKING, MSN 2023, 2023, : 367 - 373
  • [33] A DGA Domain Name Detection Method of Multilevel Feature Probability
    Yang, Hongyu
    Zhang, Tao
    Zhang, Liang
    Hu, Ze
    Xie, Lixia
    Beijing Youdian Daxue Xuebao/Journal of Beijing University of Posts and Telecommunications, 2024, 47 (05): : 86 - 91
  • [34] DGA domain name detection based on BiGRU-MCNN
    Chen, ChaoQuan
    Pan, LeiLei
    Xie, XiaoLan
    2019 4TH INTERNATIONAL CONFERENCE ON INTELLIGENT INFORMATION PROCESSING (ICIIP 2019), 2019, : 316 - 320
  • [35] Towards effective detection of elderly falls with CNN-LSTM neural networks
    García, Enol
    Villar, Mario
    Fáñez, Mirko
    Villar, José R.
    de la Cal, Enrique
    Cho, Sung-Bae
    Neurocomputing, 2022, 500 : 231 - 240
  • [36] Intrusion Detection Mechanism for Large Scale Networks using CNN-LSTM
    Karanam, Lokesh
    Pattanaik, Kiran Kumar
    Aldmour, Rakan
    2020 13TH INTERNATIONAL CONFERENCE ON DEVELOPMENTS IN ESYSTEMS ENGINEERING (DESE 2020), 2020, : 323 - 328
  • [37] Hybrid Feature Optimization for Voice Spoof Detection Using CNN-LSTM
    Neelima, Medikonda
    Prabha, I. Santi
    TRAITEMENT DU SIGNAL, 2024, 41 (02) : 717 - 727
  • [38] A CNN-LSTM hybrid network for automatic seizure detection in EEG signals
    Shalini Shanmugam
    Selvathi Dharmar
    Neural Computing and Applications, 2023, 35 : 20605 - 20617
  • [39] Intrusion Detection Using Attention-Based CNN-LSTM Model
    Al-Omar, Ban
    Trabelsi, Zouheir
    ARTIFICIAL INTELLIGENCE APPLICATIONS AND INNOVATIONS, AIAI 2023, PT I, 2023, 675 : 515 - 526
  • [40] Detection of Anomalous Behavioural Patterns In University Environment Using CNN-LSTM
    Esan, Dorcas Oladayo
    Owolawi, Pius A.
    Tu, Chuling
    PROCEEDINGS OF 2020 23RD INTERNATIONAL CONFERENCE ON INFORMATION FUSION (FUSION 2020), 2020, : 225 - 232