节点文献
APEA:一种恶意URL新型识别方法
APEA:a novel method for identifying malicious URL
【摘要】 在数字化时代,随着网络攻击手段不断进化,恶意网页识别已成为网络安全领域的一大挑战。传统的卷积神经网络在恶意网页检测中取得了显著成果,但无法捕获长距离依赖关系且语义捕获能力有限。因此,设计一种新型深度学习模型自适应位置感知嵌入与注意力(adaptive positionally-aware embedding and attention, APEA),为恶意网页识别提出研究新思路。APEA模型采用比Transformer模型更细粒度的字符级信息,以增强模型对恶意统一资源定位符(uniform resource locator, URL)文本中细节特征的感知能力;与Transformer模型类似,将输入的嵌入信息与位置编码相结合,以显式注入顺序信息;新增了全局信息共享机制,有效融合局部和全局特征,以提升模型对复杂恶意URL模式的识别能力。设计的自适应动态权重机制,使模型能够根据不同输入灵活调整多头自注意力机制的各个头的权重,从而捕获更多特征。实验结果表明,相较于现有的基于机器学习和深度学习恶意URL检测方法,APEA模型在检测的准确率、精确率、召回率、F1分数上都表现更好。消融实验结果表明,全局信息共享机制和自适应调整的动态权重更新机制对模型性能的提升均有贡献,相比去掉这两个机制的模型,APEA模型各指标均有2.8%左右的提升。
【Abstract】 In the digital era, with the continuous evolution of cyberattack methods, the identification of malicious web pages has become a major challenge in the field of network security.Traditional convolutionalneural networks have achieved remarkable results in the detection of malicious web pages, but they are unable to capture longdistance dependencies and have limited semantic capture capabilities.Therefore, a novel deep learning modelnamed APEA was designed and implemented, offering a new research direction for the identification of malicious webpages. APEA model adopted character-level information with a finer granularity than the Transformer to enhance the model’s perception of detailed features in malicious URL texts. Similar to the Transformer, input embedding were combined with positional encoding to explicitly incorporate sequential information.Additionally,a global information sharing mechanism wasincorporated to effectively integrate local and global features,thereby improving the model’s ability to recognize complex malicious URL patterns.An adaptive dynamic weight update mechanism was designed,enabling the model to flexibly adjust the weights of each head in the multi-head self-attention mechanism according to different input,thus capturing more features.Experimental results showed that compared with existing machine learning and deep learning-based malicious URL detection methods,APEA achieved better performance in terms of detection accuracy,precision,recall,and F1 score.Ablation experiment results indicated that both the global information sharing mechanism and the adaptive dynamic weight update mechanism contribute to the improvement of model performance.Compared with the model with these two mechanisms removed,the APEA model achieves an improvement of approximately 2.8% across all metrics.
【Key words】 APEA; malicious URL identification; global information; Transformer;
- 【文献出处】 网络与信息安全学报 ,Chinese Journal of Network and Information Security , 编辑部邮箱 ,2025年06期
- 【分类号】TP393.08
- 【下载频次】33