Malicious DNS detection by combining improved transformer and CNN

被引:0
|
作者
Li, Heyu [1 ]
Li, Zhangmeizhi [2 ]
Zhang, Shuyan [2 ]
Pu, Xiao [2 ]
机构
[1] Changchun Sci Tech Univ, Admiss Off, Changchun 130600, Peoples R China
[2] China Univ Petr Beijing Karamay, Petr Inst, Karamay 834000, Peoples R China
来源
SCIENTIFIC REPORTS | 2024年 / 14卷 / 01期
关键词
Transformer; CNN; Malicious DNS detection; Network security; Multiple attention mechanism;
D O I
10.1038/s41598-024-81189-1
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
With the widespread application of the Internet, network security issues have become increasingly prominent. As an important infrastructure of the Internet, the domain name server has been attacked in various forms. Traditional methods for detecting malicious domain servers are usually based on rules or feature engineering, requiring a large amount of manual participation and rule library updates. These methods cannot adapt to the constantly changing threat environment. In response to these issues, this study first improves the Transformer by adjusting its attention head and encoding method. Then, the model is combined with convolutional neural networks. Finally, a block-based ensemble classifier is used for classification detection. The relevant outcomes showed that the average accuracy score of the proposed method was as high as 95.8 points, the average detection time score was 96.8 points, the average feature extraction ability score of the model was 96.3 points, and the overall performance score was 97.6 points. This method has significant advantages over traditional methods in terms of accuracy and detection time, providing a new tool for detecting malicious domain servers.
引用
收藏
页数:16
相关论文
共 50 条
  • [1] Combining transformer and CNN for object detection in UAV imagery
    Hendria, Willy Fitra
    Phan, Quang Thinh
    Adzaka, Fikriansyah
    Jeong, Cheol
    ICT EXPRESS, 2023, 9 (02): : 258 - 263
  • [2] DNS dataset for malicious domains detection
    Marques, Claudio
    Malta, Silvestre
    Magalhaes, Joao Paulo
    DATA IN BRIEF, 2021, 38
  • [3] Detection of Malicious Payload Distribution Channels in DNS
    Kara, A. Mert
    Binsalleeh, Hamad
    Mannan, Mohammad
    Youssef, Amr
    Debbabi, Mourad
    2014 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2014, : 853 - 858
  • [4] Malicious DNS Tunneling Detection in Real-Traffic DNS Data
    Lambion, Danielle
    Josten, Michael
    Olumofin, Femi
    De Cock, Martine
    2020 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2020, : 5736 - 5738
  • [5] DNS Traffic Analysis for Malicious Domains Detection
    Ghafir, Ibrahim
    Prenosil, Vaclav
    2ND INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING AND INTEGRATED NETWORKS (SPIN) 2015, 2015, : 613 - 618
  • [6] DNS Graph Mining For Malicious Domain Detection
    Hau Tran
    An Nguyen
    Phuong Vo
    Tu Vu
    2017 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2017, : 4680 - 4685
  • [7] An Object Detection Model for Power Lines With Occlusions Combining CNN and Transformer
    Shi, Weicheng
    Lyu, Xiaoqin
    Han, Lei
    IEEE TRANSACTIONS ON INSTRUMENTATION AND MEASUREMENT, 2025, 74
  • [8] An Improved Ensemble Deep Learning Model Based on CNN for Malicious Website Detection
    Do, Nguyet Quang
    Selamat, Ali
    Lim, Kok Cheng
    Krejcar, Ondrej
    ADVANCES AND TRENDS IN ARTIFICIAL INTELLIGENCE: THEORY AND PRACTICES IN ARTIFICIAL INTELLIGENCE, 2022, 13343 : 497 - 504
  • [9] Research on blockchain abnormal transaction detection technology combining CNN and transformer structure
    Wang, Zhiqiang
    Ni, Anfa
    Tian, Ziqing
    Wang, Ziyi
    Gong, Yongguang
    COMPUTERS & ELECTRICAL ENGINEERING, 2024, 116
  • [10] Detection of Malicious Domains Using Passive DNS with XGBoost
    Silveira, Marcos Rogerio
    Cansian, Adriano Mauro
    Kobayashi, Hugo Koji
    2020 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENCE AND SECURITY INFORMATICS (ISI), 2020, : 59 - 61