节点文献
基于神经网络的恶意DNS流量检测方法
Malicious DNS traffic detection based neural networks
【摘要】 针对目前机器学习检测恶意DNS流量提取流量特征方面的效率不高、检测准确率和检测速度较低等问题,提出了一种结合频域特征聚合分析和神经网络算法的恶意DNS流量检测方法FDS-DL。首先,通过离散傅里叶变换将DNS流量从时域空间转换到频域空间,在保留流量关键信息的同时大幅压缩数据规模;然后,利用卷积神经网络对处理后的频域序列数据进行分类。实验结果表明,与当前主流的几种检测方法相比,FDS-DL对恶意DNS流量的检测精度和F1_score性能最优。
【Abstract】 To solve the problems of low detection accuracy and speed caused by low efficiency in extracting traffic features using machine learning to detect malicious DNS traffic, a malicious DNS traffic detection method FDS-DL was proposed, which combines frequency domain feature aggregation analysis and neural networks algorithms. Firstly, DNS traffic was converted from time-domain space to frequency-domain space through discrete Fourier transform, which could significantly compress the data scale while retaining key log information. Then, convolutional neural network was used to classify the processed frequency domain sequence data. The experimental results show that compared with several mainstream detection methods, FDS-DL has a higher accuracy in identifying malicious DNS traffic and F1_score is optimal.
【Key words】 frequency domain; DFT; neural network; convolutional neural network; malicious domain name;
- 【文献出处】 通信学报 ,Journal on Communications , 编辑部邮箱 ,2024年S2期
- 【分类号】TP183;TP393.08
- 【下载频次】18