<p>The proliferation of distributed network architectures offers scalability and resilience; however, it simultaneously introduces security problems. Notably, malicious domains pose non-negligible threats because they are the cornerstone of Distributed Denial-of-Service (DDoS). As a result, identifying malicious domains is a fundamental task for distributed network security. Traditional methods, reliant on feature engineering and large-scale labeled datasets, struggle to keep pace with the constantly evolving threat landscape. Recent deep learning models, especially Transformer-based architectures, have achieved promising results, but still face the following three challenges: (1) insufficient generalization for cross-domain domain name detection; (2) learning difficulty for cross-domain domain name detection; and (3) contradiction between parameter efficiency and domain adaptation, among other challenges. To confront these limitations, we propose a novel <b>M</b>ulti-<b>E</b>xpert <b>A</b>daptive <b>D</b>omain framework for <b>M</b>alicious <b>D</b>omain <b>D</b>etection (<b>MEAD-MDD</b>) that leverages pre-trained models with efficient adaptation mechanisms. Extensive experiments across multiple benchmark datasets demonstrate that MEAD-MDD outperforms all state-of-the-art baselines. Notably, MEAD-MDD achieves significant improvements in detecting highly camouflaged malicious domains. Furthermore, ablation studies validate that MEAD-MDD enhances cross-domain detection performance while simultaneously reducing computational costs by optimizing only a small subset of parameters, thus maintaining efficiency without sacrificing accuracy. Crucially, our model exhibits robustness against adversarial attacks and domain shifts, making it highly suitable for real-world deployment. These findings underscore the effectiveness of MEAD-MDD in confronting the growing challenges of malicious domain detection and highlight its potential to enhance contemporary cybersecurity defenses significantly.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Combating evolving threats: A robust malicious domain detection framework for distributed networks

  • Yinuo Jin,
  • Fei He,
  • Yi Zhu,
  • Hao Ren

摘要

The proliferation of distributed network architectures offers scalability and resilience; however, it simultaneously introduces security problems. Notably, malicious domains pose non-negligible threats because they are the cornerstone of Distributed Denial-of-Service (DDoS). As a result, identifying malicious domains is a fundamental task for distributed network security. Traditional methods, reliant on feature engineering and large-scale labeled datasets, struggle to keep pace with the constantly evolving threat landscape. Recent deep learning models, especially Transformer-based architectures, have achieved promising results, but still face the following three challenges: (1) insufficient generalization for cross-domain domain name detection; (2) learning difficulty for cross-domain domain name detection; and (3) contradiction between parameter efficiency and domain adaptation, among other challenges. To confront these limitations, we propose a novel Multi-Expert Adaptive Domain framework for Malicious Domain Detection (MEAD-MDD) that leverages pre-trained models with efficient adaptation mechanisms. Extensive experiments across multiple benchmark datasets demonstrate that MEAD-MDD outperforms all state-of-the-art baselines. Notably, MEAD-MDD achieves significant improvements in detecting highly camouflaged malicious domains. Furthermore, ablation studies validate that MEAD-MDD enhances cross-domain detection performance while simultaneously reducing computational costs by optimizing only a small subset of parameters, thus maintaining efficiency without sacrificing accuracy. Crucially, our model exhibits robustness against adversarial attacks and domain shifts, making it highly suitable for real-world deployment. These findings underscore the effectiveness of MEAD-MDD in confronting the growing challenges of malicious domain detection and highlight its potential to enhance contemporary cybersecurity defenses significantly.