An Improved Capsule Network for DGA Domain Detection

Hongyu Yang,Tao Zhang,Ze Hu,Liang Zhang,Xiang Cheng
DOI: https://doi.org/10.1109/msn60784.2023.00061
2023-01-01
Abstract:The malicious domains generated by domain generation algorithm (DGA) are a threat to network security and the existing DGA domain detection methods commonly represent domain features by scalars, resulting in damage to the feature structure. To cope with the above issues, an improved capsule network for DGA domain detection was proposed. Firstly, the original samples were numerically processed and converted to the domain word vectors. Secondly, we built a n-grams feature extraction network based on residual network to extract domain features. Thirdly, we designed an improved capsule network to classify the domains according to the domain features. The domain features were converted to primary capsules. Finally, an improved dynamic routing algorithm was used to generate high-level capsules, whose lengths were used as auxiliary information for detecting domains. The experimental results show that compared with state-of-the-art methods, our method has remarkable detection performance.
What problem does this paper attempt to address?