D3-SACNN: DGA Domain Detection With Self-Attention Convolutional Network

4Citations
Citations of this article
7Readers
Mendeley users who have this article in their library.

Abstract

Botnets are currently one of the main cyber security threats. In order to enhance the concealment, botnets usually use Domain Generation Algorithm (DGA) to establish communication between bots and command and control servers. Character-based deep learning methods are widely researched in the classification of DGA domains to detect botnets and have achieved good results. But the pronounceable DGA domain detection is still a challenge, since the linguistic statistical characteristics of the pronounceable DGA domains and benign domains are very similar. We propose a multi-head self-attention convolutional network method for DGA domain classification task. We use a shallow convolutional neural network to extract hidden features of domain characters. The multi-head self-attention mechanism with different input values is used to effectively obtain the relationship between the characters and the extracted implicit features, which will help us more effectively distinguish between pronounceable DGA domains and benign domains. Experiments on public data show that our model can effectively detect various types of DGA domains. Especially for the pronounceable DGA domains, our method is significantly better than other detection methods.

Cite

CITATION STYLE

APA

Zhao, K., Guo, W., Qin, F., & Wang, X. (2022). D3-SACNN: DGA Domain Detection With Self-Attention Convolutional Network. IEEE Access, 10, 69250–69263. https://doi.org/10.1109/ACCESS.2021.3127913

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free