Malicious DNS detection by combining improved transformer and CNN

被引:0
|
作者
Li, Heyu [1 ]
Li, Zhangmeizhi [2 ]
Zhang, Shuyan [2 ]
Pu, Xiao [2 ]
机构
[1] Changchun Sci Tech Univ, Admiss Off, Changchun 130600, Peoples R China
[2] China Univ Petr Beijing Karamay, Petr Inst, Karamay 834000, Peoples R China
来源
SCIENTIFIC REPORTS | 2024年 / 14卷 / 01期
关键词
Transformer; CNN; Malicious DNS detection; Network security; Multiple attention mechanism;
D O I
10.1038/s41598-024-81189-1
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
With the widespread application of the Internet, network security issues have become increasingly prominent. As an important infrastructure of the Internet, the domain name server has been attacked in various forms. Traditional methods for detecting malicious domain servers are usually based on rules or feature engineering, requiring a large amount of manual participation and rule library updates. These methods cannot adapt to the constantly changing threat environment. In response to these issues, this study first improves the Transformer by adjusting its attention head and encoding method. Then, the model is combined with convolutional neural networks. Finally, a block-based ensemble classifier is used for classification detection. The relevant outcomes showed that the average accuracy score of the proposed method was as high as 95.8 points, the average detection time score was 96.8 points, the average feature extraction ability score of the model was 96.3 points, and the overall performance score was 97.6 points. This method has significant advantages over traditional methods in terms of accuracy and detection time, providing a new tool for detecting malicious domain servers.
引用
收藏
页数:16
相关论文
共 50 条
  • [31] CNN-based malicious user detection in social networks
    Hong, Taekeun
    Choi, Chang
    Shin, Juhyun
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2018, 30 (02):
  • [32] DETECTION OF MALICIOUS DNS AND WEB SERVERS USING GRAPH-BASED APPROACHES
    Jia, Jinyuan
    Dong, Zheng
    Li, Jie
    Stokes, Jack W.
    2021 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP 2021), 2021, : 2625 - 2629
  • [33] DNS Covert Channel Detection Based on Self-Generated Malicious Traffic
    Diao, Jia-Wen
    Fang, Bin-Xing
    Tian, Zhi-Hong
    Wang, Zhong-Ru
    Song, Shou-You
    Wang, Tian
    Cui, Xiang
    Jisuanji Xuebao/Chinese Journal of Computers, 2022, 45 (10): : 2190 - 2206
  • [34] YOLOv8-CDD: an improved concrete defect detection method combined CNN with transformer
    Wang, Chengyin
    Chen, Bo
    Li, Yonglong
    Wang, Haoran
    Tan, Liguo
    Zhang, Yunan
    Zhang, Hua
    MEASUREMENT SCIENCE AND TECHNOLOGY, 2025, 36 (01)
  • [35] An Imbalanced Malicious Domains Detection Method Based on Passive DNS Traffic Analysis
    Liu, Zhenyan
    Zeng, Yifei
    Zhang, Pengfei
    Xue, Jingfeng
    Zhang, Ji
    Liu, Jiangtao
    SECURITY AND COMMUNICATION NETWORKS, 2018,
  • [36] Automatic Detection of Transformer Components in Inspection Images Based on Improved Faster R-CNN
    Liu, Ziquan
    Wang, Huifang
    ENERGIES, 2018, 11 (12)
  • [37] Detecting Malicious Activity with DNS Backscatter
    Fukuda, Kensuke
    Heidemann, John
    IMC'15: PROCEEDINGS OF THE 2015 ACM CONFERENCE ON INTERNET MEASUREMENT CONFERENCE, 2015, : 197 - 210
  • [38] Malicious Circuit Detection for Improved Hardware Security
    Bharath, R.
    Sabari, G. Arun
    Krishna, Dhinesh Ravi
    Prasathe, Arun
    Harish, K.
    Mohankumar, N.
    Devi, M. Nirmala
    SECURITY IN COMPUTING AND COMMUNICATIONS (SSCC 2015), 2015, 536 : 464 - 472
  • [39] Transportation Mode Detection Combining CNN and Vision Transformer with Sensors Recalibration Using Smartphone Built-In Sensors
    Tian, Ye
    Hettiarachchi, Dulmini
    Kamijo, Shunsuke
    SENSORS, 2022, 22 (17)
  • [40] A CNN-Transformer Network Combining CBAM for Change Detection in High-Resolution Remote Sensing Images
    Yin, Mengmeng
    Chen, Zhibo
    Zhang, Chengjian
    REMOTE SENSING, 2023, 15 (09)