节点文献

基于神经网络的恶意DNS流量检测方法

Malicious DNS traffic detection based neural networks

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 单康康袁书宏陈文智王志波

【Author】 SHAN Kangkang;YUAN Shuhong;CHEN Wenzhi;WANG Zhibo;Information Technology Center, Zhejiang University;College of Computer Science, Zhejiang University;School of Cyber Science and Technology, Zhejiang University;

【机构】 浙江大学信息技术中心浙江大学计算机科学与技术学院浙江大学网络空间安全学院

【摘要】 针对目前机器学习检测恶意DNS流量提取流量特征方面的效率不高、检测准确率和检测速度较低等问题,提出了一种结合频域特征聚合分析和神经网络算法的恶意DNS流量检测方法FDS-DL。首先,通过离散傅里叶变换将DNS流量从时域空间转换到频域空间,在保留流量关键信息的同时大幅压缩数据规模;然后,利用卷积神经网络对处理后的频域序列数据进行分类。实验结果表明,与当前主流的几种检测方法相比,FDS-DL对恶意DNS流量的检测精度和F1_score性能最优。

【Abstract】 To solve the problems of low detection accuracy and speed caused by low efficiency in extracting traffic features using machine learning to detect malicious DNS traffic, a malicious DNS traffic detection method FDS-DL was proposed, which combines frequency domain feature aggregation analysis and neural networks algorithms. Firstly, DNS traffic was converted from time-domain space to frequency-domain space through discrete Fourier transform, which could significantly compress the data scale while retaining key log information. Then, convolutional neural network was used to classify the processed frequency domain sequence data. The experimental results show that compared with several mainstream detection methods, FDS-DL has a higher accuracy in identifying malicious DNS traffic and F1_score is optimal.

【基金】 未来互联网试验设施FITI项目试验节点建设资助项目(发改高技[2016]2533号);中国高校产学研创新基金资助项目(No.2022HS046)~~
  • 【文献出处】 通信学报 ,Journal on Communications , 编辑部邮箱 ,2024年S2期
  • 【分类号】TP183;TP393.08
  • 【下载频次】18
节点文献中: 

本文链接的文献网络图示:

本文的引文网络