基于多通道卷积和注意力网络的DNS隐蔽信道检测算法
DOI:
作者:
作者单位:

电子科技大学

作者简介:

通讯作者:

中图分类号:

TP393

基金项目:

四川省科技计划项目(2022YFG0328)、国家发改委项目子课题(2022201914)


DNS Covert Channel Detection Algorithm Based on Multi- channel Convolution Neural Network and Attention Mechanism
Author:
Affiliation:

Information Center,University of Electronic Science and Technology of China

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    DNS(domain name system)隐蔽信道是一种利用DNS协议实现数据泄露的网络攻击手段,受到诸多APT组织的青睐,给网络空间安全带来了严重威胁。针对传统机器学习方法对特征依赖性强、误报率高的问题,提出一种融合多通道卷积和注意力网络的DNS隐蔽信道检测算法。该算法基于DNS请求与响应双向流,首先将残差结构和并行卷积相结合,采用不同大小的卷积核提取并融合多尺度特征信息,实现不同感受野特征的捕获;其次引入通道注意力机制增加卷积通道关键信息的提取能力,丰富网络模型的表达能力;最后采用softmax函数实现DNS隐蔽信道的检测。实验结果表明,所提模型能有效检测DNS隐蔽信道,平均准确率、精确率和召回率分别为:96.42%、97.82%和96.16%,优于传统方法。

    Abstract:

    DNS(domain name system) covert channel is a kind of cyberattacks to achieve data leakage, which is favored by many APT organizations and poses a serious threat to cyberspace security. Aiming at the problem that traditional machine learning methods rely on selected features and are easy to over-fit, a DNS covert channel detection method fusing multi-scale convolution neural network and attention mechanism is proposed. This method focuses on the bidirectional flow of DNS request and response. Firstly, multi-scale convolutional kernels are used to extract the spatial features of DNS flow in parallel. It can extract richer context information features by increasing the width of backbone network. Then an attention mechanism is introduced to further mine the information of fused feature maps between multi convolutional channels. Finally, a softmax classifier is used to implement the detection of DNS covert channels. The experimental results show that the proposed model can effectively detect the DNS covert channel, and the average accuracy, precision rate and recall rate are 96.42%, 97.82% and 96.16% respectively, which are higher than the traditional method.

    参考文献
    相似文献
    引证文献
引用本文

李晓冬,张映敏,李育强,等. 基于多通道卷积和注意力网络的DNS隐蔽信道检测算法[J]. 科学技术与工程, , ():

复制
分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2023-10-24
  • 最后修改日期:2024-05-20
  • 录用日期:2024-05-21
  • 在线发布日期:
  • 出版日期:
×
亟待确认版面费归属稿件,敬请作者关注