Javascript must be enabled to continue!
KDTM: Multi-Stage Knowledge Distillation Transfer Model for Long-Tailed DGA Detection
View through CrossRef
As the most commonly used attack strategy by Botnets, the Domain Generation Algorithm (DGA) has strong invisibility and variability. Using deep learning models to detect different families of DGA domain names can improve the network defense ability against hackers. However, this task faces an extremely imbalanced sample size among different DGA categories, which leads to low classification accuracy for small sample categories and even classification failure for some categories. To address this issue, we introduce the long-tailed concept and augment the data of small sample categories by transferring pre-trained knowledge. Firstly, we propose the Data Balanced Review Method (DBRM) to reduce the sample size difference between the categories, thus a relatively balanced dataset for transfer learning is generated. Secondly, we propose the Knowledge Transfer Model (KTM) to enhance the knowledge of the small sample categories. KTM uses a multi-stage transfer to transfer weights from the big sample categories to the small sample categories. Furthermore, we propose the Knowledge Distillation Transfer Model (KDTM) to relieve the catastrophic forgetting problem caused by transfer learning, which adds knowledge distillation loss based on the KTM. The experimental results show that KDTM can significantly improve the classification performance of all categories, especially the small sample categories. It can achieve a state-of-the-art macro average F1 score of 84.5%. The robustness of the KDTM model is verified using three DGA datasets that follow the Pareto distributions.
Title: KDTM: Multi-Stage Knowledge Distillation Transfer Model for Long-Tailed DGA Detection
Description:
As the most commonly used attack strategy by Botnets, the Domain Generation Algorithm (DGA) has strong invisibility and variability.
Using deep learning models to detect different families of DGA domain names can improve the network defense ability against hackers.
However, this task faces an extremely imbalanced sample size among different DGA categories, which leads to low classification accuracy for small sample categories and even classification failure for some categories.
To address this issue, we introduce the long-tailed concept and augment the data of small sample categories by transferring pre-trained knowledge.
Firstly, we propose the Data Balanced Review Method (DBRM) to reduce the sample size difference between the categories, thus a relatively balanced dataset for transfer learning is generated.
Secondly, we propose the Knowledge Transfer Model (KTM) to enhance the knowledge of the small sample categories.
KTM uses a multi-stage transfer to transfer weights from the big sample categories to the small sample categories.
Furthermore, we propose the Knowledge Distillation Transfer Model (KDTM) to relieve the catastrophic forgetting problem caused by transfer learning, which adds knowledge distillation loss based on the KTM.
The experimental results show that KDTM can significantly improve the classification performance of all categories, especially the small sample categories.
It can achieve a state-of-the-art macro average F1 score of 84.
5%.
The robustness of the KDTM model is verified using three DGA datasets that follow the Pareto distributions.
Related Results
Participation of paediatric patients in primary dental care before and after a dental general anaesthetic
Participation of paediatric patients in primary dental care before and after a dental general anaesthetic
Abstract
Purpose
The aim of this retrospective study is to determine children’s attendance and
experience of preventative interventions and operativ...
Uneven Distribution of Metallic Ions in Deposits Precipitated in the Koshijihara DGA CO2 Removal Units
Uneven Distribution of Metallic Ions in Deposits Precipitated in the Koshijihara DGA CO2 Removal Units
Abstract
304 stainless steel has been suffering from general corrosion in CO2 removal units using a high concentration DGA solution in a natural gas processing plant...
Electrochemical Behavior of Carbon Steel in Carbon Dioxide-Saturated Diglycolamine Solutions
Electrochemical Behavior of Carbon Steel in Carbon Dioxide-Saturated Diglycolamine Solutions
The electrochemical behavior of carbon steel in diglycolamine (DGA) solutions saturated with carbon dioxide (CO2) under 4.5 MPa pressure was investigated using potentiodynamic pola...
A Comprehensive Review of Distillation in the Pharmaceutical Industry
A Comprehensive Review of Distillation in the Pharmaceutical Industry
Distillation processes play a pivotal role in the pharmaceutical industry for the purification of active pharmaceutical ingredients (APIs), intermediates, and solvent recovery. Thi...
Ecological Relationships between Mule Deer and White‐Tailed Deer in Southeastern Arizona
Ecological Relationships between Mule Deer and White‐Tailed Deer in Southeastern Arizona
Niche relationships between the desert mule deer (Odocoileus hemionus crooki) and Coues white—tailed deer (Odocoileus virginianus couesi) were studied in the San Cayetano and Dos C...
Power Transformer Fault Diagnosis using DGA based on Three Gas Ratio and Fuzzy Logic
Power Transformer Fault Diagnosis using DGA based on Three Gas Ratio and Fuzzy Logic
For power system equipment with oil as insulating medium such as power transformer, Dissolved Gas Analysis (DGA) of oil is very helpful method in order to detect faults below oil l...
Principles and Modes of Distillation in Desalination Process
Principles and Modes of Distillation in Desalination Process
Distillation has been a very important separation technique used over many centuries. This technique is diverse and applicable in different fields and for different substances. Dis...
Treatment of Disseminated Granuloma Annulare with Oral Vitamin E: ‘Primum Nil Nocere'
Treatment of Disseminated Granuloma Annulare with Oral Vitamin E: ‘Primum Nil Nocere'
<b><i>Background:</i></b> Disseminated granuloma annulare (DGA) is a benign and usually asymptomatic skin disease. However, many patients feel aesthetically...

