Malicious domain name detection method and device, electronic equipment and storage medium
By building a dynamic relationship diagram of domain name space-time and combined with a meta-learning strategy optimization model, the existing malicious domain name detection methods have solved the problems of high computing resource consumption and insufficient robustness of malicious domain name variants, and efficient and accurate malicious domain name detection is achieved.
Patent Information
- Application Number
- CN202510326525.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-19
- Publication Date
- 2025-06-06
AI Technical Summary
The existing malicious domain name detection methods consume high computing resources during large-scale data processing, resulting in delayed detection process and lack sufficient robustness to variants of malicious domain names.
A malicious domain name detection method is proposed. By obtaining domain name feature data, a time-stamped domain name spatiotemporal dynamic relationship diagram is constructed, a spatiotemporal dynamic feature is extracted using the spatiotemporal neural network model, and a meta-learning strategy is used for model optimization to improve the accuracy and real-timeness of detection.
It reduces the consumption of computing resources, improves the accuracy and real-timeness of malicious domain name detection, and enhances the detection capabilities of new or unseen malicious domain names.
Smart Images

Figure CN120110779A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of network information analysis, and in particular to a malicious domain name detection method, device, electronic device and storage medium. Background Art
[0002] With the rapid development of the Internet, domain names, as the core infrastructure for network communication and information exchange, have received increasing attention for their security. However, the frequent appearance of malicious domain names poses a serious threat to network security and is often used to carry out various network attacks such as phishing attacks, distributed denial of service attacks, malware propagation, and data theft. These malicious activities not only endanger the privacy and property security of individual users, but also have a significant impact on the critical data of servers and network infrastructure.
[0003] Malicious domain name detection methods in related technologies mainly include rule-based, statistical and machine learning-based methods. Although these methods can identify known malicious domain names to a certain extent, many malicious domain name detection technologies, especially those based on deep learning or complex graph structures, usually require a lot of computing resources and time. Especially when processing large-scale data, excessive computing costs may cause delays in the detection process and affect real-time performance.
[0004] In addition, related technologies usually rely on a large amount of well-labeled training data. If the data quality is low or the data set is not diverse enough, the generalization ability of the model may be limited, resulting in unsatisfactory detection results. For example, attackers often disguise themselves through domain name obfuscation, encryption and other means. When faced with attackers' constantly changing domain name generation strategies and diverse malicious domain name variants, related technical detection methods lack sufficient robustness against these variants, making it difficult to accurately identify modified or encrypted malicious domain names. Summary of the invention
[0005] The main purpose of the embodiments of the present application is to propose a malicious domain name detection method, device, electronic device and storage medium, aiming to reduce the consumption of computing resources and improve the accuracy and real-time performance of malicious domain name detection.
[0006] To achieve the above purpose, an embodiment of the present application provides a method for detecting malicious domain names, the method comprising:
[0007] Acquire domain name feature data, and preprocess the domain name feature data to obtain a training data set;
[0008] Based on the training data set, construct a domain name spatiotemporal dynamic relationship graph with timestamps according to the domain name relationships between the domain names;
[0009] Convolving the spatiotemporal dynamic relationship graph of the domain name through a spatiotemporal graph neural network model to obtain the spatiotemporal dynamic features of the domain name;
[0010] A meta-learning strategy is adopted to transform the malicious domain name detection task into a plurality of meta-learning tasks, and similarities between the meta-learning tasks are modeled based on Gaussian processes according to the spatiotemporal dynamic characteristics;
[0011] Optimizing the inner and outer layers of the spatiotemporal graph neural network model according to the similarity;
[0012] The domain name to be detected is input into the optimized spatiotemporal graph neural network model to obtain a predicted label.
[0013] In some embodiments, the obtaining of domain name feature data and preprocessing of the domain name feature data to obtain a training data set includes the following steps:
[0014] Collect domain name strings, domain name registration information, Internet Protocol addresses, domain name system records, website content, network behavior data and timestamps from multiple data sources to obtain domain name feature data;
[0015] Performing data cleaning, standardization, redundancy removal, and noise reduction processing on the domain name feature data to obtain preprocessed data;
[0016] Performing data labeling on the pre-processed data according to performance parameters and network threat levels of the domain names;
[0017] A training data set is obtained according to the pre-processed data after data annotation.
[0018] In some embodiments, the constructing of a domain name spatiotemporal dynamic relationship graph with timestamps based on the training data set and the domain name relationships between the domain names comprises the following steps:
[0019] A domain name spatiotemporal relationship graph is constructed with domain names as nodes and at least one domain name relationship between domain names as edges, wherein the domain name relationship includes one of the Internet Protocol address shared between domain names, the domain name registration information similar between domain names, and the domain name system records similar between domain names;
[0020] The domain name spatiotemporal relationship graph is decomposed into several subgraphs of time steps according to the timestamp to obtain a domain name spatiotemporal dynamic relationship graph with timestamp.
[0021] In some embodiments, the convolution of the domain name spatiotemporal dynamic relationship graph through the spatiotemporal graph neural network model to obtain the spatiotemporal dynamic features of the domain name includes the following steps:
[0022] Obtaining a node feature matrix according to the domain name spatiotemporal dynamic relationship diagram;
[0023] Performing graph convolution on the node feature matrix at each time step through a graph convolution weight matrix to obtain node spatial features;
[0024] Based on a preset step size range, the node feature matrix of different time steps is subjected to time series convolution by a time series convolution weight matrix to obtain node time series features;
[0025] Fusion of the node spatial features and the node temporal features to obtain fusion features;
[0026] The fused features are used through an activation function to generate an updated node feature matrix, and the updated node feature matrix is used as the spatiotemporal dynamic features of the domain name.
[0027] In some embodiments, the meta-learning strategy is used to transform the malicious domain name detection task into a plurality of meta-learning tasks, and the similarities between the meta-learning tasks are modeled based on the Gaussian process according to the spatiotemporal dynamic characteristics, including the following steps:
[0028] Defining a number of meta-learning tasks according to the malicious domain name detection task, wherein each of the meta-learning tasks corresponds to the domain name relationship in a different time period;
[0029] Aggregating the spatiotemporal dynamic features of the same time period to obtain a task feature vector for each meta-learning task;
[0030] The similarity between the tasks is obtained according to the Euclidean distance of the task feature vectors between the meta-learning tasks.
[0031] In some embodiments, the inner and outer layer optimization of the spatiotemporal graph neural network model according to the similarity comprises the following steps:
[0032] The inner layer of the spatiotemporal graph neural network model is optimized with the goal of minimizing the loss function of the current task, and the time step parameter is updated according to the similarity by a gradient descent algorithm;
[0033] The spatiotemporal graph neural network model is outer-optimized with the goal of minimizing the loss functions on multiple tasks, and the meta-learning parameters are updated according to the similarity through a gradient descent algorithm.
[0034] In some embodiments, the method further comprises the following steps:
[0035] Obtaining a true label of the predicted label;
[0036] Determine a parameter gradient according to the predicted label and the true label;
[0037] Normalizing the parameter gradient to obtain the task importance weight;
[0038] Update the model parameters of the spatiotemporal graph neural network model according to the task importance weights.
[0039] To achieve the above purpose, another aspect of the embodiment of the present application provides a malicious domain name detection device, the device comprising:
[0040] The first module is used to obtain domain name feature data and pre-process the domain name feature data to obtain a training data set;
[0041] The second module is used to construct a domain name spatiotemporal dynamic relationship graph with timestamps based on the training data set and the domain name relationships between the domain names;
[0042] The third module is used to convolve the spatiotemporal dynamic relationship graph of the domain name through a spatiotemporal graph neural network model to obtain the spatiotemporal dynamic features of the domain name;
[0043] The fourth module is used to transform the malicious domain name detection task into a plurality of meta-learning tasks by adopting a meta-learning strategy, and to model the similarities between the meta-learning tasks based on a Gaussian process according to the spatiotemporal dynamic characteristics;
[0044] The fifth module optimizes the inner and outer layers of the spatiotemporal graph neural network model according to the similarity;
[0045] The sixth module inputs the domain name to be detected into the optimized spatiotemporal graph neural network model to obtain a predicted label.
[0046] To achieve the above objective, another aspect of an embodiment of the present application provides an electronic device, the electronic device comprising a memory and a processor, the memory storing a computer program, and the processor implementing the above method when executing the computer program.
[0047] To achieve the above objective, another aspect of an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and the computer program implements the above method when executed by a processor.
[0048] The embodiments of the present application include at least the following beneficial effects: the present application provides a malicious domain name detection method, device, electronic device and storage medium, the scheme obtains domain name feature data, pre-processes the domain name feature data to obtain a training data set; based on the training data set, a domain name spatiotemporal dynamic relationship graph with timestamps is constructed according to the domain name relationship between domain names; the domain name spatiotemporal dynamic relationship graph is convoluted by the spatiotemporal graph neural network model to obtain the spatiotemporal dynamic characteristics of the domain name; a meta-learning strategy is used to convert the malicious domain name detection task into several meta-learning tasks, and the similarity between the meta-learning tasks is modeled based on the spatiotemporal dynamic characteristics based on the Gaussian process; the spatiotemporal graph neural network model is optimized internally and externally according to the similarity to adjust the model parameters. The domain name to be detected is input into the optimized spatiotemporal graph neural network model to obtain a predicted label. The present application can reduce the consumption of computing resources and improve the accuracy and real-time performance of detecting new or unseen malicious domain names. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] Figure 1 is a flow chart of a malicious domain name detection method provided by an embodiment of the present application;
[0050] Figure 2 The embodiment of this application provides Figure 1 Specific method step flow chart of step S101;
[0051] Figure 3 The embodiment of this application provides Figure 1 Specific method step flow chart of step S102;
[0052] Figure 4 The embodiment of this application provides Figure 1 Specific method step flow chart of step S103;
[0053] Figure 5 The embodiment of this application provides Figure 1 Specific method step flow chart of step S104;
[0054] Figure 6 The embodiment of this application provides Figure 1 Specific method step flow chart of step S105;
[0055] Figure 7 is a flowchart of continuous learning and model updating provided by an embodiment of the present application;
[0056] Figure 8 is a flow chart of a malicious domain name detection method provided by another embodiment of the present application;
[0057] Fig. 9 This is a schematic diagram of the relationship between the inner and outer layer optimization of the model provided in the embodiment of the present application;
[0058] Fig.10 It is a structural schematic diagram of a malicious domain name detection device provided in an embodiment of the present application;
[0059] Fig.11 is a schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present application; DETAILED DESCRIPTION
[0060] In order to make the purpose, technical solutions and advantages of the present application clearer, the present application is further described in detail below in conjunction with the accompanying drawings and examples. It should be understood that the specific embodiments described herein are only used to explain the present application and are not intended to limit the present application. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the embodiments of the present application. They are only examples of devices and methods consistent with some aspects of the embodiments of the present application as detailed in the attached claims.
[0061] It is understood that the terms "first", "second", etc. used in this application can be used to describe various concepts in this article, but unless otherwise specified, these concepts are not limited by these terms. These terms are only used to distinguish one concept from another concept. For example, without departing from the scope of the embodiment of the present application, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the words "if" and "if" as used herein can be interpreted as "at the time of" or "when" or "in response to determination".
[0062] The terms "at least one", "multiple", "each", "any", etc. used in this application, at least one includes one, two or more, multiple includes two or more, each refers to each of the corresponding multiple, and any refers to any one of the multiple.
[0063] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art to which this application belongs. The terms used herein are only for the purpose of describing the embodiments of this application and are not intended to limit this application.
[0064] The malicious domain name detection method provided in the embodiment of the present application relates to the field of network information analysis technology. The malicious domain name detection method provided in the embodiment of the present application can be applied to a terminal, can also be applied to a server, and can also be software running in a terminal or a server. In some embodiments, the terminal can be a smart phone, a tablet computer, a laptop computer, a desktop computer, a smart speaker, a smart watch, and a car terminal, etc., but is not limited to this; the server side can be configured as an independent physical server, or it can be configured as a server cluster or distributed system composed of multiple physical servers, and can also be configured as a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. The server can also be a node server in a blockchain network; the software can be an application that implements the malicious domain name detection method, etc., but is not limited to the above forms.
[0065] The present application can be used in many general or special computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, etc. The present application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present application can also be practiced in distributed computing environments, in which tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.
[0066] Figure 1 is an optional flowchart of the malicious domain name detection method provided in the embodiment of the present application. Figure 1 The method may include but is not limited to steps S101 to S106.
[0067] Step S101, obtaining domain name feature data, and preprocessing the domain name feature data to obtain a training data set.
[0068] Step S102, based on the training data set, construct a domain name spatiotemporal dynamic relationship graph with timestamps according to the domain name relationships between the domain names.
[0069] Step S103, convolving the spatiotemporal dynamic relationship graph of the domain name through the spatiotemporal graph neural network model to obtain the spatiotemporal dynamic features of the domain name.
[0070] Step S104, using a meta-learning strategy to transform the malicious domain name detection task into a number of meta-learning tasks, and based on the spatiotemporal dynamic characteristics, the similarities between the meta-learning tasks are modeled based on the Gaussian process.
[0071] Step S105, optimizing the inner and outer layers of the spatiotemporal graph neural network model according to similarity.
[0072] Step S106: input the domain name to be detected into the optimized spatiotemporal graph neural network model to obtain a predicted label.
[0073] Specifically, domain name feature data is obtained. The domain name feature data can be obtained from various domain name data sources on the Internet, wherein each data point of the domain name feature data contains multiple attributes for describing the characteristics of the domain name at a specific point in time. Exemplarily, the domain name feature data may include but is not limited to domain name string, registration date, registrant information, Internet Protocol (IP) address, Domain Name System (DNS) record type, website content summary, access frequency, geographic distribution, traffic pattern, abnormal behavior indicators and other attributes.
[0074] It should be noted that in actual malicious domain name detection tasks, in order to improve the accuracy and reliability of monitoring, the data attributes involved may far exceed the number of data attributes provided in this embodiment. The increase in attributes can provide more comprehensive information for the model. These data attributes may include various detailed sensor data, operating status parameters, environmental factors, etc. Each attribute is potentially important for malicious domain name detection, and the embodiments of this application do not impose specific restrictions.
[0075] After obtaining the domain name feature data, the domain name feature data is preprocessed to obtain a training data set. In order to accurately distinguish the normal operation status and various malicious states of the domain name, manual labeling, automated labeling tools or semi-supervised learning methods can be used to preprocess the domain name, such as labeling the domain name as "normal" or "malicious". The samples after labeling constitute the original training data set for subsequent model training.
[0076] In malicious domain name detection, there are complex relationships and dynamically changing behavior patterns between domain names. In order to effectively capture these spatio-temporal dynamic relationships, this embodiment combines spatio-temporal graph neural networks (ST-GNN) with meta-learning strategies to achieve dynamic modeling and rapid adaptation of domain name relationships.
[0077] First, based on the training data set, a domain name spatiotemporal dynamic relationship graph with timestamps is constructed according to the domain name relationship between domain names. The domain name spatiotemporal dynamic relationship graph consists of nodes and edges, where each node represents a domain name and is used to construct a relationship graph between domain names. Through the definition of nodes, the relationship and interaction between domain names can be represented and analyzed in the graph structure; edges represent the relationship between domain names, such as common resolved IP addresses, similar registration information, and DNS record similarity.
[0078] After obtaining the spatiotemporal dynamic relationship graph of domain names, the spatiotemporal dynamic relationship graph of domain names is convolved through the spatiotemporal graph neural network model to obtain the spatiotemporal dynamic features of domain names. The spatiotemporal graph neural network model can better understand the dynamic changes of domain names between different time nodes. Therefore, the spatiotemporal graph neural network model is used to convolve the spatiotemporal dynamic relationship graph of domain names, and the spatiotemporal features of domain name relationships are extracted by combining the graph structure and time dynamics to obtain the spatiotemporal dynamic features of domain names.
[0079] Then, a meta-learning strategy is used to transform the malicious domain name detection task into several meta-learning tasks. According to the spatiotemporal dynamic characteristics, the similarities between the meta-learning tasks are modeled based on the Gaussian process. When dealing with malicious domain name detection tasks, the spatiotemporal graph neural network model needs to have the ability to quickly adapt to new tasks. Traditional machine learning methods often require a large amount of data for training and are slow to adapt to new tasks. In order to improve the generalization ability and adaptability of the spatiotemporal graph neural network model in malicious domain name detection, a meta-learning strategy is introduced to apply meta-learning to the parameter optimization of the spatiotemporal graph neural network.
[0080] Specifically, the core idea of meta-learning is to enable the model to quickly adapt to new tasks by learning how to learn. By defining multiple tasks, the model can learn under different spatiotemporal graph structures. Therefore, the malicious domain name detection task is transformed into multiple meta-learning tasks, each of which corresponds to the domain name relationship pattern in a different time period. By training on these tasks, the spatiotemporal graph neural network can learn the ability to adapt to changes in different domain name relationships.
[0081] In order to enable the model to adapt to new tasks sequentially, the task adaptation process is divided into two stages: task-level adaptation (inner layer optimization) and global-level optimization (outer layer optimization). The inner and outer layers of the spatiotemporal graph neural network model are optimized according to similarity, and the model parameters are adjusted.
[0082] During the optimization process, tasks with high similarity will receive more weight, thus playing a greater role in updating model parameters. Each stage is driven by different learning strategies and optimization processes. The inner optimization focuses on how to quickly adjust parameters on a given task, while the outer optimization focuses on how to generalize the model through cross-task learning. Through task similarity modeling, the model can quickly adapt to new tasks using a small amount of labeled data, reducing the need for large-scale labeled data. Through inner and outer layer optimization, the spatiotemporal graph neural network can quickly use existing knowledge for reasoning when faced with new malicious domain name detection tasks.
[0083] After the model training optimization is completed, the optimized spatiotemporal graph neural network model can be applied to the malicious domain name detection task. When a domain name request is received, the domain name to be detected is input into the optimized spatiotemporal graph neural network model to obtain a predicted label. The domain name to be detected is mapped to the spatiotemporal relationship graph as a new node, and the edge is defined based on its relationship with the known domain name. The node features are updated through the dynamic message passing mechanism, and the optimized spatiotemporal graph neural network model is used for prediction, and the predicted label is output to achieve real-time malicious domain name identification and timely response to network threats.
[0084] For example, assuming that the preset probability threshold is 0.5, the label of the domain name can be determined based on the predicted probability distribution and the preset threshold. When the probability of the "malicious" label is greater than 0.5, it is determined to be a malicious domain name. If the probability of the predicted "normal" label is 0.8 and the probability of the "malicious" label is 0.2, the output predicted label is the "normal" label.
[0085] It should be noted that in order to improve the diversity and robustness of detection, rule-based detection methods or other machine learning models (such as random forests) can also be combined to output prediction labels.
[0086] In this embodiment, a large model framework that integrates spatiotemporal graph neural network and meta-learning strategy is proposed. This framework constructs a spatiotemporal relationship graph to dynamically capture the spatiotemporal dynamic features between domain names. Combined with the meta-learning method, the model can quickly adapt to new tasks. This method effectively reduces the consumption of computing resources and improves the ability of real-time detection. By introducing spatiotemporal dynamic features, the adaptability of the model to data quality and diversity is enhanced; by utilizing the powerful expression ability of the graph neural network, the robustness to domain name confusion and variants is improved; at the same time, the use of meta-learning strategies simplifies the training and deployment process of the model, reduces maintenance costs, and enhances the scalability and flexibility of the system. Through the above innovations, this embodiment comprehensively solves the problems of high computing overhead, strong data dependence, insufficient robustness, and high model complexity in related technologies, further improves the accuracy, real-time, efficiency, and adaptability of detecting new or unseen malicious domain names, and enhances the overall network security protection capabilities.
[0087] In some embodiments, reference Figure 2 , step S101 may include but is not limited to steps S201 to S204.
[0088] Step S201, domain name character string, domain name registration information, Internet Protocol address, domain name system record, website content, network behavior data and timestamp are collected from multiple data sources to obtain domain name feature data.
[0089] Step S202, performing data cleaning, standardization, redundancy removal, and noise reduction processing on the domain name feature data to obtain pre-processed data.
[0090] Step S203: labeling the pre-processed data according to the performance parameters and network threat level of the domain name.
[0091] Step S204, obtaining a training data set based on the pre-processed data after data annotation.
[0092] In step S201 of some embodiments, domain name feature data can be obtained by collecting domain name strings, domain name registration (WHOIS) information, Internet Protocol addresses, domain name system records, website content, network behavior data and timestamps from multiple data sources when the system is started or through periodic triggering.
[0093] In step S201 of some other embodiments, a third-party data provider or real-time captured network traffic data may be used as domain name feature data.
[0094] Optionally, after the domain name feature data is collected, in order to ensure the quality and consistency of the data, the collected domain name feature data is cleaned, standardized, redundancy removed, and noise reduced to obtain pre-processed data.
[0095] The pre-processed data is labeled according to the performance parameters and network threat level of the domain name. If the domain name involves phishing content or is associated with a known malicious IP, it is labeled as "malicious"; otherwise, it is labeled as "normal". Considering the variety of malicious domain names, such as "phishing", "malware", "command and control", etc., the "malicious" label can be further divided according to the specific type of malicious domain name.
[0096] For example, taking a certain network environment as an example, the collected data includes domain name strings, registration dates, etc. At a certain point in time, it is observed that the domain name is associated with a known malicious IP, and the website content involves phishing information, then the data point is marked as a malicious domain name of the "phishing" type.
[0097] The pre-processed data after data annotation is sorted to obtain a training data set suitable for model training.
[0098] In some embodiments, reference Figure 3 , step S102 may include but is not limited to steps S301 to S302.
[0099] Step S301, constructing a domain name spatiotemporal relationship graph with domain names as nodes and at least one domain name relationship between domain names as edges, wherein the domain name relationship includes one of an Internet Protocol address shared between domain names, similar domain name registration information between domain names, and similar domain name system records between domain names.
[0100] Step S302, decomposing the domain name spatiotemporal relationship graph into several subgraphs of time steps according to the timestamps, and obtaining a domain name spatiotemporal dynamic relationship graph with timestamps.
[0101] Specifically, a domain name spatiotemporal relationship graph is constructed with domain names as nodes and at least one domain name relationship between domain names as edges, wherein the domain name relationship includes one of an Internet Protocol address shared between domain names, similar domain name registration information between domain names, and similar domain name system records between domain names.
[0102] Optionally, if there are multiple domain name relationships between domain names, a multi-edge single-attribute design can be used to create an independent edge for each domain name relationship, or a single-edge multi-attribute design can be used to assign multiple domain name relationships to one edge.
[0103] In this embodiment, each node represents a domain name, and the edges between nodes represent the relationship and interaction between domain names. Various relationships between domain names constitute an edge set ε. In this embodiment, the edge set can be expressed as:
[0104] ε={(x i ,x j )|Shared_IP(x i ,x j )∨Similar_WHOIS(x i ,x j )∨DNS_Similarity(x i ,x j )} (1);
[0105] In formula (1), Shared_IP(x i ,x j ) indicates domain name x i and domain name x j Internet Protocol addresses shared between i ,x j ) indicates domain name x i and domain name x j Similar domain name registration information between i ,xj ) indicates domain name x i and domain name x j DNS records that are similar between .
[0106] It should be noted that, in addition to the Internet Protocol addresses shared between domain names, similar domain name registration information between domain names, and similar domain name system records between domain names, domain name relationships may also include common access behaviors between domain names. The embodiments of the present application are merely exemplary and are not specifically limited, as long as they can reflect the interaction and association between domain names.
[0107] Furthermore, each edge carries a timestamp t, reflecting the change of the relationship and constructing a spatiotemporal relationship graph of the domain name.
[0108] ε t ={(x i ,x j ,t)∣(x i ,x j )∈ε}(2);
[0109] In formula (2), ε t It represents the edge set at time t, recording the dynamic changes of domain name relationships.
[0110] The evolution of domain name relationships over time is captured by timestamps, which enhances the model's perception of temporal dynamics. As time goes by, the relationship between domain names changes.
[0111] In order to reflect this change, the spatiotemporal graph is decomposed into subgraphs of multiple time steps to represent the changes in domain name relationships at each time point. The domain name spatiotemporal relationship graph is decomposed into several subgraphs of time steps according to the timestamp to obtain the domain name spatiotemporal dynamic relationship graph with timestamp.
[0112] Exemplarily, at time step t, the structure of the graph is represented as G t =(V t ,E t ), where V t is a node set, E t It is an edge set.
[0113] In this embodiment, by constructing a spatiotemporal relationship graph containing timestamps, the multidimensional relationship between domain names and time (such as shared IP, similar WHOIS information, DNS record similarity, etc.) and its dynamic changes are fully reflected, which helps to effectively model these complex relationships through spatiotemporal graph neural networks in the future, and realize in-depth mining of the spatiotemporal dynamic characteristics between domain names.
[0114] In some embodiments, reference Figure 4 , step S103 may include but is not limited to steps S401 to S405.
[0115] Step S401, obtaining a node feature matrix according to the domain name spatiotemporal dynamic relationship diagram.
[0116] Step S402, performing graph convolution on the node feature matrix of each time step through the graph convolution weight matrix to obtain the node spatial features.
[0117] Step S403, based on a preset step size range, performing time series convolution on the node feature matrices of different time steps through a time series convolution weight matrix to obtain node time series features.
[0118] Step S404: fusing the node spatial features and the node temporal features to obtain fused features.
[0119] Step S405: The fused features are activated through an activation function to generate an updated node feature matrix, and the updated node feature matrix is used as the spatiotemporal dynamic features of the domain name.
[0120] Taking into account that current graph neural networks generally lack a real-time update mechanism for dynamic changes in time, resulting in the inability to fully and effectively reflect the latest changes in domain name relationships, the embodiment of the present application designs a dynamic message transmission mechanism that comprehensively considers neighbor information and historical information to ensure that node features can be updated in real time and fully reflect the latest dynamics of domain name relationships, so as to enhance the model's perception of time series changes.
[0121] Specifically, the node feature matrix is obtained according to the spatiotemporal dynamic relationship graph of the domain name. After the spatiotemporal dynamic relationship graph is constructed, each node will be assigned an initial feature vector, and the node feature matrix represents the matrix of the feature vector set of all domain name nodes at a certain moment. For example, the node feature matrix H (t) That is, it is the matrix of the feature set of all domain name nodes at time t.
[0122] The node feature matrix of each time step is convolved through the graph convolution weight matrix to obtain the node spatial features.
[0123] For example, for the node feature matrix of each time step, the association between the current node and each neighbor node is calculated, and the influence of the neighbor node features is adjusted through the graph convolution weight matrix to obtain the node spatial features. The formula is as follows:
[0124]
[0125] In formula (3), It is the node space feature, indicating the message from the neighbor node, reflecting the relationship between the current domain name and its neighbors; is the neighbor set of node i, indicating other domain names that are directly related to the current domain name; c ik is the spatial normalization coefficient, which is used to ensure the stability of message transmission; W(t) is the graph convolution weight matrix at time t.
[0126] Based on the preset step range, the node feature matrix of different time steps is temporally convolved through the temporal convolution weight matrix to obtain the node temporal features, where the step range represents the time step considered and determines the degree of utilization of historical information.
[0127] Exemplarily, assuming that the preset step range is L, the node feature matrix of the current node in the past L time steps is obtained according to the preset step range, and the node feature matrices of different time steps are temporally convolved through the temporal convolution weight matrix to obtain the node temporal features. The formula is as follows:
[0128]
[0129] In formula (4), is the node time series feature, which represents the message from the historical time step and reflects the historical behavior and relationship changes of the domain name; W (t,l) represents the temporal convolution weight matrix of time step l; d il is the time normalization coefficient, which is used to capture the historical information of different time steps.
[0130] The node spatial features and node temporal features are fused to obtain the fused features, and the fused features are used to generate an updated node feature matrix through an activation function, and the updated node feature matrix is used as the spatiotemporal dynamic features of the domain name.
[0131] Specifically, the node spatial features and node temporal features are added to obtain the fusion features, and then the nonlinear characteristics are introduced through the activation function to generate an updated node feature matrix, and the updated node feature matrix is used as the spatiotemporal dynamic features of the domain name. By combining the graph structure and time dynamics, a dynamic message transmission mechanism is designed so that the node features can be updated in real time, thereby extracting the spatiotemporal features of the domain name relationship. The formula is as follows:
[0132]
[0133] In formula (5), H (t+1) is the updated node feature matrix, which combines the information from neighbors and history to capture spatiotemporal dynamic characteristics; σ is the activation function.
[0134] In this embodiment, the dynamic message transmission mechanism ensures that node features can reflect the latest relationship changes and behavior patterns in real time, enhances the model's ability to respond to dynamic threats, and significantly improves the model's ability to identify malicious domain names disguised by obfuscation, encryption, etc. Even in the face of attackers using a variety of variant technologies, the detection effect is still stable and reliable, improving the robustness and security of the system.
[0135] In some embodiments, reference Figure 5 , step S104 may include but is not limited to steps S501 to S503.
[0136] Step S501, defining a plurality of meta-learning tasks according to the malicious domain name detection task, wherein each meta-learning task corresponds to a domain name relationship in a different time period.
[0137] Step S502: Aggregate the spatiotemporal dynamic features of the same time period to obtain a task feature vector for each meta-learning task.
[0138] Step S503, obtaining the similarity between tasks according to the Euclidean distance of the task feature vectors between the meta-learning tasks.
[0139] Specifically, several meta-learning tasks are defined based on the malicious domain name detection task, where each meta-learning task corresponds to the domain name relationship in different time periods. Contains a space-time graph G i and the corresponding label y i ,By defining multiple tasks, the model can learn under different spatiotemporal graph structures, ,thus improving its ability to quickly adapt to unknown malicious domain name ,patterns.
[0140] At the same time, in the malicious domain name detection task, different attack patterns usually show certain similarities. For example, some malicious domain names may be associated by sharing the same IP address or similar DNS records, while others may be propagated through temporal similarities. The similarity between tasks usually reflects their commonalities in spatiotemporal graph structure and temporal evolution. In traditional meta-learning, tasks are assumed to be independent, while the embodiments of the present application believe that the similarity between tasks can provide valuable guidance for learning. Therefore, in this embodiment, the covariance function of the Gaussian process is used to quantify this similarity. Specifically, the Euclidean distance between task feature vectors is used to measure the similarity between tasks.
[0141] For example, the spatiotemporal dynamic features of the same time period are aggregated to obtain the task feature vector of each meta-learning task, and the similarity between tasks is obtained based on the Euclidean distance between the task feature vectors of the meta-learning tasks. and the second task Task and The similarity can be calculated by the following formula:
[0142]
[0143] In formula (6), f i and fj The tasks are and The task feature vectors represent their spatiotemporal dynamic characteristics and temporal behaviors; is the similarity between tasks, reflecting the correlation between the two tasks in terms of spatiotemporal characteristics and behavioral patterns.
[0144] By calculating the similarities between all tasks, we can obtain a task similarity matrix K, which represents the similarities between different tasks.
[0145] Optionally, using the task similarity matrix K, a weighting coefficient can be assigned to each task. This weighting mechanism is based on the similarity between tasks. Tasks with high similarity will receive higher weights and thus be given priority in the subsequent optimization process. Task weight w i It can be adjusted according to the value of the similarity matrix. The calculation formula of the task weight is as follows:
[0146]
[0147] Through this weighting mechanism, the similarity between tasks affects their importance in the subsequent training process.
[0148] In some embodiments, reference Figure 6 , step S105 may include but is not limited to steps S601 to S602.
[0149] Step S601, optimize the inner layer of the spatiotemporal graph neural network model with the goal of minimizing the loss function of the current task, and update the time step parameters according to the similarity through the gradient descent algorithm.
[0150] Step S602, performing outer layer optimization on the spatiotemporal graph neural network model with the goal of minimizing the loss functions on multiple tasks, and updating the meta-learning parameters according to the similarity through the gradient descent algorithm.
[0151] Specifically, the inner layer of the spatiotemporal graph neural network model is optimized with the goal of minimizing the loss function of the current task, and the time step parameters are updated according to the similarity through the gradient descent algorithm. In the meta-learning framework, inner layer optimization is a training process for a specific task. For the spatiotemporal graph neural network, task-level adaptation means local optimization through gradient descent on a given spatiotemporal graph structure to quickly adapt to the characteristics of the current task.
[0152] For example, for the task Assume that there is an initial model parameter The goal is to update the model parameters by gradient descent to minimize the loss function on the task In each task Above, the training process of the model is:
[0153]
[0154] In formula (8), is the parameter of the task at step t; α is the learning rate of the inner layer optimization; It is the loss function of the task, which represents the prediction error of the model on the task.
[0155] In the inner optimization stage, the similarity between tasks can be used as prior knowledge to influence the direction and magnitude of parameter adjustment. For example, if two tasks are highly similar, the model can draw more on the knowledge learned from the other task when adjusting parameters.
[0156] Through inner layer optimization, the spatiotemporal graph neural network can quickly adjust its parameters in each task, allowing the model to efficiently learn the spatiotemporal characteristics and domain name relationships of the current task.
[0157] Furthermore, in addition to the inner layer optimization, the spatiotemporal graph neural network model needs to be optimized at the outer layer with the goal of minimizing the loss function on multiple tasks, and the meta-learning parameters are updated according to the similarity through the gradient descent algorithm. The outer layer optimization takes into account the relationship between multiple tasks. By training on different tasks, the model can learn common rules and features, so that when encountering new tasks, it can quickly adjust and achieve better performance.
[0158] For example, the goal of the outer optimization is to learn initial parameters that can adapt to different spatiotemporal graph tasks by minimizing the loss functions on multiple tasks. The update formula of the outer optimization is:
[0159]
[0160] In formula (9), φ is the meta-learning parameter of the model; β is the learning rate of the outer layer optimization; is the task loss function, which represents the average loss of all tasks.
[0161] In the outer optimization stage, a weighting coefficient can be assigned to each task based on the calculated task similarity matrix, so that when the model updates parameters, it can consider more task information with high similarity to the current task, thereby improving the generalization ability of the model.
[0162] In some embodiments, reference Figure 7 The malicious domain name detection method may also include steps S701 to S704.
[0163] Step S701, obtaining the true label of the predicted label.
[0164] Step S702, determining the parameter gradient according to the predicted label and the true label.
[0165] Step S703, normalize the parameter gradient to obtain the task importance weight.
[0166] Step S704: Update the model parameters of the spatiotemporal graph neural network model according to the task importance weights.
[0167] Specifically, the newly annotated data is used to fine-tune the spatiotemporal graph neural network model in real time according to the predicted labels, and a task importance weighted measurement mechanism is introduced to update the model parameters of the model.
[0168] First, obtain the real label of the predicted label. In order to enable the model to continuously adapt to new threats and domain name variants and maintain efficient detection performance, this embodiment uses the predicted label identified by the model to mark potential malicious domain names. The real label is obtained through security analysts or automated feedback to achieve continuous learning and optimization of the model.
[0169]
[0170] In formula (10), represents the set of prediction results of the preliminary test, {(x i ,y i )} contains the domain name and its predicted label; it represents the annotated true label set, which is used to guide further training of the model.
[0171] The model is fine-tuned online through a continuous feedback mechanism to update parameters and ensure that the model can learn the latest threat patterns and domain name variants. After online fine-tuning, the model can quickly adapt to new tasks and new threats, and maintain continuous improvement in detection capabilities.
[0172] At the same time, considering that the model may catastrophically forget old knowledge due to parameter changes during online learning, although the traditional EWC regularization method can prevent catastrophic forgetting by constraining the changes in model parameters, its core assumption is that all tasks have equal impact on parameters when updating. However, in reality, in the malicious domain name detection task, different tasks have different requirements for model parameters. Some tasks may be more important to certain parameters, while others may be less critical.
[0173] Therefore, in order to further enhance the effect of EWC, this embodiment introduces a task importance weighted measurement mechanism, and constructs a task importance measurement by calculating the influence of each task on each model parameter during the training process. This measurement takes into account the gradient influence of each task on each parameter in the model learning process, as well as the degree of change of each spatiotemporal relationship in the task. The parameter gradient is determined according to the predicted label and the true label. After obtaining the parameter gradient, the parameter gradient is further normalized to obtain the task importance weight.
[0174] Exemplarily, the parameter gradients of the loss to the model parameters are calculated based on the predicted labels and the true labels, and then the gradient normalization technique is used to calculate the importance of the task and weight the importance of different parameters according to the size of the gradient:
[0175]
[0176] In formula (11), Represents task T i The parameter θ j gradient.
[0177] Finally, the model parameters of the spatiotemporal graph neural network model are updated according to the task importance weights. For parameters with larger gradients, it means that they are more important to the current task, so stronger regularization constraints need to be imposed on these parameters, while for parameters with smaller gradients, there is no need to impose too many constraints.
[0178] In EWC, the sum of squared parameter differences is used as a regularization term. In order to introduce task importance weighting, the EWC loss function is designed as:
[0179]
[0180] In formula (12), λ i It is task T i The importance weight, θ j are the parameters of the spatiotemporal graph neural network model, is the optimal value of the parameter in the old task, Task Importance(T i ,θ j ) is weighted according to the impact of each task on the parameter.
[0181] This weighted strategy allows different tasks to have different interference levels on model parameters during the update process, thereby more accurately controlling the parameter adjustment between tasks. Continuously optimizing and updating model parameters ensures that the model can learn the latest threat patterns and domain name variants, improving the model's detection performance.
[0182] Optionally, to reduce the computational overhead and complexity of the online learning process, the model can be updated in batches periodically or a transfer learning approach can be adopted.
[0183] The embodiment of the present application introduces a task importance weighted measurement mechanism into the EWC regularization method, calculates the influence of each task on the model parameters, and adjusts the parameter update strategy in a targeted manner, thereby enhancing the adaptability of the model to different tasks, preventing catastrophic forgetting in the online learning process, maintaining the efficient detection performance and adaptability of the model, and ensuring that it can retain important knowledge of old tasks while learning new tasks, so as to cope with ever-changing network threats and domain name generation strategies.
[0184] The following is a detailed introduction and description of the solution of the embodiment of the present invention in conjunction with a specific application example.
[0185] Reference Figure 8 , the malicious domain name detection method of the embodiment of the present application can be divided into four stages, including data collection and annotation, spatiotemporal graph neural network modeling, meta-learning strategy and online learning update.
[0186] An embodiment of the present application provides a malicious domain name detection system, which includes a data collection module, a data processing module, a graph construction module, a model training module, a detection module, and an online learning module, which are used to implement the above four stages.
[0187] Specifically, in the process of malicious domain name detection, first, when the system is started or triggered regularly, the data collection module collects various attribute data (such as domain name strings, WHOIS information, DNS records, etc.) from various domain name data sources on the Internet, and constructs an original training set containing multiple attributes to provide comprehensive domain name feature data for subsequent model training.
[0188] When the data collection module completes data collection, it triggers the data processing module to perform data preprocessing and labeling. The data processing module cleans and standardizes the collected raw data to remove redundant and noisy data. Then, based on threat intelligence and domain name performance parameters, security analysts or automated tools label the domain names and classify them as "normal" or specific malicious types, obtaining a labeled training data set to provide accurate training labels for subsequent model training and improve the supervised learning effect of the model.
[0189] Next, the graph construction module receives the training data set sent by the data processing module and constructs a spatiotemporal relationship graph based on the relationships between domain names (such as shared IP, similar WHOIS information, DNS record similarity, etc.). Each domain name is a node in the graph, and the relationships between domain names are edges with timestamps. The specific relationships include:
[0190] Shared_IP: Edges between a domain and other domains that share the same resolved IP address.
[0191] Similar_WHOIS: Edges between a domain name and other domain names with similar WHOIS information.
[0192] DNS_Similarity: Edges between a domain name and other domain names with similar DNS records.
[0193] The dynamic relationships and behavior patterns between domain names are captured through the graph construction module. After completing the construction of the spatiotemporal graph, a spatiotemporal dynamic relationship graph of multiple time steps is obtained, providing structured input for the graph neural network.
[0194] It should be noted that the graph construction module may also adopt other graph construction methods based on community detection or clustering algorithms to reflect different types of domain name relationships.
[0195] Then, the model training module performs spatiotemporal feature extraction and meta-learning strategy application based on the spatiotemporal dynamic relationship graph provided by the graph construction module.
[0196] Specifically, refer to Fig. 9 , use the spatiotemporal graph neural network (ST-GNN) to perform convolution operations on the constructed spatiotemporal relationship graph to extract the spatiotemporal dynamic features of the domain name. The specific operations include:
[0197] (1) Perform graph convolution on the node feature matrix of each time step and combine the feature information of neighboring nodes.
[0198] (2) Design a dynamic message delivery mechanism so that node features can be updated in real time to reflect the latest changes in domain name relationships.
[0199] The meta-learning strategy is introduced to decompose the task. By converting the malicious domain name detection task into multiple meta-learning tasks, the model is trained to quickly adapt to new tasks. Specifically, it includes:
[0200] (1) Define multiple meta-learning tasks, each task corresponds to the domain name relationship pattern in a different time period.
[0201] (2) Use Gaussian process to model the similarity between tasks and assign task weights based on the task similarity matrix.
[0202] (3) Perform inner optimization (task-level adaptation) and outer optimization (global-level optimization) to improve the model’s generalization ability on new tasks.
[0203] After training with the model training module, a trained spatiotemporal graph neural network model can be obtained. The model has the ability to quickly adapt to new tasks, can achieve efficient learning and feature extraction of complex domain name relationships and dynamic behaviors, and improve the detection accuracy and adaptability of the model.
[0204] It is understandable that the model training module can also adopt other neural network architectures (such as Transformer) or different feature extraction methods to adapt to different data effects and detection requirements.
[0205] The detection module obtains the domain name to be detected based on real-time domain name requests or periodic detection task triggers, inputs the domain name to be detected into the trained spatiotemporal graph neural network model, and uses the spatiotemporal features extracted by the model to classify it and determine whether the domain name is a malicious domain name.
[0206] Specifically, the detection module obtains the relevant attributes and relationship information of the domain name to be detected in real time, maps the domain name and its relationship into the spatiotemporal graph structure, extracts the corresponding feature vector, uses the trained model to make predictions, and outputs the maliciousness label of the domain name (such as "malicious" or "normal").
[0207] The detection module can realize real-time or near real-time identification of malicious domain names and respond to network threats in a timely manner.
[0208] Finally, the online learning module receives domain name requests and behavior data in real time through the network monitoring system, uses the existing model to perform preliminary detection, and marks potential malicious domain names. Through security analysts or automated feedback mechanisms, the real labels are obtained to achieve continuous learning and optimization of the model.
[0209] Using the newly annotated domain name data, we fine-tune the spatiotemporal graph neural network model online and update the model parameters to ensure that the model can learn the latest threat patterns and domain name variants. At the same time, we introduce a task importance weighted measurement mechanism to enhance the model's adaptability to different tasks and prevent catastrophic forgetting by calculating the influence of each task on the model parameters.
[0210] In some embodiments, to implement the malicious domain name detection method provided in the embodiments of the present application, the data flow configuration of the embodiment is as follows:
[0211] 1. Data collection technical parameters:
[0212] Time range: A sliding time window mechanism is used to perform incremental collection every 5 minutes, retaining historical data for the last 30 days.
[0213] Collection frequency: WHOIS information is updated synchronously every hour, DNS records are polled and collected every 15 minutes, and network behavior data is captured in real-time streaming.
[0214] Output data specifications:
[0215] Format specification: The processed data is serialized in Protocol Buffers binary format. The field structure includes:
[0216] message DomainRecord{
[0217] string domain_name = 1; / / standard punycode encoding
[0218] repeated IPAddress resolved_ips=2; / / IPv4 / IPv6 dual stack record
[0219] Timestamp registration_date = 3; / / ISO 8601 extended format
[0220] WHOISInfo whois_data=4; / / Structured nested message
[0221] BehaviorProfile behavior_stats = 5; / / 256-dimensional feature vector
[0222] }
[0223] Annotation:
[0224] (1) Initial screening and labeling layer:
[0225] Automated rule engine: 32 regular expression templates are preset (including IDN domain name features, TLD abnormal combinations, etc.) - Confidence threshold: a decision boundary of 0.7 is set, and those with confidence lower than this value are transferred to manual labeling.
[0226] (2) Manual annotation layer:
[0227] Annotation interface: A real-time rendering tool based on WebAssembly that supports multi-view collaboration (WHOIS / DNS / traffic three-window linkage).
[0228] Labeling efficiency: It has been verified that a single labeler can process up to 120 items per minute with an error rate of <2%.
[0229] 2. Space-time graph construction module:
[0230] Input interface specifications:
[0231] Time window: Adopt overlapping time slicing strategy, with the basic time unit of 10 minutes, the window span of 60 minutes, and the sliding step of 5 minutes.
[0232] Data update: The node feature matrix is incrementally updated every 2 minutes, and the edge relationship data is updated in real-time through event-driven triggering.
[0233] Output structure definition:
[0234] Graph data format: The adjacency matrix is stored in CSR (Compressed Sparse Row) format, and node features are stored as Float32 tensors.
[0235] Metadata annotation: Each graph snapshot contains a timestamp, version number (64-bit hash value), checksum (SHA-256), etc. to ensure data integrity.
[0236] 3. Meta-learning adaptation strategy.
[0237] Task data interface:
[0238] Input features: The dimension of the task feature vector is fixed to 512 dimensions, and the length of the time series is unified to 144 sampling points (corresponding to a 24-hour period).
[0239] Data timeliness: The task dataset contains the behavior patterns of the past 7 days, and the time decay coefficient is set to an exponentially weighted average of λ = 0.85.
[0240] Parameter output specification:
[0241] Standard format: Model parameters are stored in block quantization, the main weight matrix uses FP16 precision, and the importance parameters retain FP32 precision.
[0242] Update frequency: The outer layer optimization performs a full update every 6 hours, and the inner layer optimization supports minute-level incremental parameter adjustments.
[0243] 4. Continuous Learning Mechanism Interface Definition
[0244] Online acquisition interface:
[0245] Data pipeline: adopts double buffer queue design, input delay is controlled within 200ms, and priority queue ensures 50ms processing time limit for urgent threat data.
[0246] Feedback mechanism: The annotation results are fed back to the system within 1500ms, and abnormal situations trigger a three-level retry mechanism (interval 50ms / 200ms / 500ms).
[0247] Model update output:
[0248] Version management: A 64-bit version identifier is generated for each update, along with a performance indicator matrix (including 12 indicators such as F1-score and ROC-AUC).
[0249] Hot update mechanism: supports imperceptible service switching within 300ms, and atomic parameter replacement operations ensure process consistency.
[0250] 5. Inter-module connection technology.
[0251] Data pipeline architecture:
[0252] From data collection to graph construction: connected through Apache Kafka message queue, using Avro serialization protocol, and the partitioning strategy adopts DomainHash modulus.
[0253] Graph data to meta-learning: shared memory mapping transmission is used, the memory database uses Redis Cluster, and the sharding strategy is based on time range.
[0254] Exception handling mechanism:
[0255] Data verification: Perform three-level verification when transferring between modules (CRC32 fast verification → SHA-256 content verification → structure legitimacy verification).
[0256] Retry strategy: Use exponential backoff retry mechanism, with a basic interval of 100ms and a maximum retry count of 5 times. If the threshold is exceeded, the message will enter the dead letter queue.
[0257] To summarize, first of all, this application constructs a spatiotemporal relationship graph with a timestamp, takes each domain name as a node in the graph, and the multidimensional relationship between domain names (such as shared IP, similar WHOIS information, DNS record similarity, etc.) as an edge with a timestamp. And use the spatiotemporal graph neural network to dynamically model these complex relationships, accurately capture the complex relationships and behavior patterns between domain names, and extract the spatiotemporal dynamic characteristics between domain names. It overcomes the problem that traditional malicious domain name detection methods are mostly based on a single feature or static relationship, such as only considering domain name string features or a single type of association relationship, and cannot fully reflect the complex and dynamic relationship between domain names. This application constructs a spatiotemporal relationship graph containing time information to comprehensively capture the multi-dimensional and dynamically changing relationships between domain names, so that the model can have a deeper understanding of the interaction and evolution patterns between domain names. When extracting domain name features, it can fully consider the dynamic changes in time and space, thereby improving the expressiveness of features and the accuracy of detection.
[0258] Secondly, this application introduces meta-strategy learning and task similarity modeling, converts the malicious domain name detection task into multiple meta-learning tasks, models the similarity between tasks through Gaussian processes, and uses meta-learning to optimize model parameters, so that the spatiotemporal graph neural network has the ability to quickly adapt to new tasks. However, the related technologies use traditional machine learning and deep learning methods, which usually require retraining or fine-tuning when facing new or unseen malicious domain names, resulting in slow adaptation and limited generalization capabilities. Compared with the related technologies, the meta-learning strategy of this application enables the model to quickly adjust parameters by learning multiple related tasks, thereby improving the adaptability and generalization capabilities of new tasks. When facing new malicious domain names, the model can quickly adjust parameters and maintain efficient detection performance; and through task similarity modeling, the model can use the commonalities between different tasks to improve detection accuracy in diverse environments, ensuring that efficient detection effects are still maintained in dynamically changing network environments.
[0259] At the same time, this application designs a dynamic message transmission mechanism, combines graph convolution operations and time series convolution operations, and comprehensively considers neighbor node information and historical time step information to capture time series dynamic features, so that node features can be updated in real time, fully reflecting the latest dynamics of domain name relationships, and improving the model's perception of time series changes. The dynamic message transmission mechanism enables node features to reflect the latest changes in domain name relationships in real time, enhancing the model's response speed and accuracy to dynamic threats. The model can quickly adapt to changes in domain name relationships and behavior patterns during real-time monitoring and detection, ensuring timely discovery and response to newly emerging malicious domain names, and reducing false positives and missed reports.
[0260] The task importance-weighted EWC regularization mechanism effectively prevents catastrophic forgetting in the model during online learning. It uses gradient normalization technology to calculate the importance of tasks and applies different regularization weights to model parameters based on the similarity between tasks, ensuring that the model can retain important knowledge of old tasks when learning new tasks. This not only improves the model's continuous learning ability, but also maintains the stability and reliability of the model in long-term operation. By weighting the importance of tasks, more accurate parameter adjustments can be made based on the differences in the importance of different tasks to model parameters, preventing catastrophic forgetting and enabling it to continue to exert efficient detection capabilities in the ever-changing network security environment.
[0261] Please refer to Fig.10 The embodiment of the present application also provides a malicious domain name detection device, which can implement the above malicious domain name detection method, and the device includes:
[0262] The first module is used to obtain domain name feature data and pre-process the domain name feature data to obtain a training data set.
[0263] The second module is used to construct a domain name spatiotemporal dynamic relationship graph with timestamps based on the training data set and the domain name relationships between domain names.
[0264] The third module is used to convolve the spatiotemporal dynamic relationship graph of the domain name through the spatiotemporal graph neural network model to obtain the spatiotemporal dynamic characteristics of the domain name.
[0265] The fourth module is used to transform the malicious domain name detection task into several meta-learning tasks using a meta-learning strategy, and to model the similarities between meta-learning tasks based on Gaussian processes according to spatiotemporal dynamic characteristics.
[0266] The fifth module optimizes the inner and outer layers of the spatiotemporal graph neural network model based on similarity.
[0267] In the sixth module, the domain name to be detected is input into the optimized spatiotemporal graph neural network model to obtain the predicted label.
[0268] It can be understood that the contents of the above method embodiments are all applicable to the present device embodiments, the functions specifically implemented by the present device embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0269] The embodiment of the present application also provides an electronic device, the electronic device includes a memory and a processor, the memory stores a computer program, and the processor implements the above malicious domain name detection method when executing the computer program. The electronic device can be any smart terminal including a tablet computer, a car computer, etc.
[0270] It can be understood that the contents of the above method embodiments are all applicable to the present device embodiments, the functions specifically implemented by the present device embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0271] Please refer to Fig.11 , Fig.11 The hardware structure of an electronic device of another embodiment is illustrated, and the electronic device includes:
[0272] The processor 901 can be implemented by a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of the present application.
[0273] The memory 902 can be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 902 can store an operating system and other application programs. When the technical solution provided in the embodiment of this specification is implemented by software or firmware, the relevant program code is stored in the memory 902, and the processor 901 calls and executes the malicious domain name detection method of the embodiment of the present application.
[0274] The input / output interface 903 is used to implement information input and output.
[0275] The communication interface 904 is used to realize the communication interaction between this device and other devices. Communication can be realized through wired methods (such as USB, network cable, etc.) or wireless methods (such as mobile network, WIFI, Bluetooth, etc.).
[0276] The bus 905 transmits information between various components of the device (eg, the processor 901 , the memory 902 , the input / output interface 903 , and the communication interface 904 ).
[0277] The processor 901 , the memory 902 , the input / output interface 903 and the communication interface 904 are connected to each other in communication within the device via a bus 905 .
[0278] An embodiment of the present application also provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the above-mentioned malicious domain name detection method is implemented.
[0279] It can be understood that the contents of the above method embodiments are all applicable to the present storage medium embodiments, the functions specifically implemented by the present storage medium embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0280] The memory, as a non-transient computer-readable storage medium, can be used to store non-transient software programs and non-transient computer executable programs. In addition, the memory may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some embodiments, the memory may optionally include a memory remotely disposed relative to the processor, and these remote memories may be connected to the processor via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0281] The embodiments described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Those skilled in the art will appreciate that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.
[0282] Those skilled in the art will appreciate that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than shown in the figures, or a combination of certain steps, or different steps.
[0283] The device embodiments described above are merely illustrative, and the units described as separate components may or may not be physically separated, that is, they may be located in one place or distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0284] Those skilled in the art will appreciate that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices may be implemented as software, firmware, hardware, or a suitable combination thereof.
[0285] The terms "first", "second", "third", "fourth", etc. (if any) in the specification of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0286] The preferred embodiments of the present invention are described above with reference to the accompanying drawings, but the scope of the rights of the present invention is not limited thereto. Any modification, equivalent substitution and improvement made by a person skilled in the art without departing from the scope and essence of the present invention should be within the scope of the rights of the present invention.
Claims
1. A method for detecting malicious domain names, characterized in that: The method comprises the following steps: Acquire domain name feature data, and preprocess the domain name feature data to obtain a training data set; Based on the training data set, construct a domain name spatiotemporal dynamic relationship graph with timestamps according to the domain name relationships between the domain names; Convolving the spatiotemporal dynamic relationship graph of the domain name through a spatiotemporal graph neural network model to obtain the spatiotemporal dynamic features of the domain name; A meta-learning strategy is adopted to transform the malicious domain name detection task into a plurality of meta-learning tasks, and similarities between the meta-learning tasks are modeled based on Gaussian processes according to the spatiotemporal dynamic characteristics; Optimizing the inner and outer layers of the spatiotemporal graph neural network model according to the similarity; The domain name to be detected is input into the optimized spatiotemporal graph neural network model to obtain a predicted label.
2. The method according to claim 1, characterized in that The step of obtaining domain name feature data and preprocessing the domain name feature data to obtain a training data set includes the following steps: Collect domain name strings, domain name registration information, Internet Protocol addresses, domain name system records, website content, network behavior data and timestamps from multiple data sources to obtain domain name feature data; Performing data cleaning, standardization, redundancy removal, and noise reduction processing on the domain name feature data to obtain preprocessed data; Performing data labeling on the pre-processed data according to performance parameters and network threat levels of the domain names; A training data set is obtained according to the pre-processed data after data annotation.
3. The method according to claim 2, characterized in that The process of constructing a domain name spatiotemporal dynamic relationship graph with timestamps based on the training data set and the domain name relationships between the domain names comprises the following steps: A domain name spatiotemporal relationship graph is constructed with domain names as nodes and at least one domain name relationship between domain names as edges, wherein the domain name relationship includes one of the Internet Protocol address shared between domain names, the domain name registration information similar between domain names, and the domain name system records similar between domain names; The domain name spatiotemporal relationship graph is decomposed into several subgraphs of time steps according to the timestamp to obtain a domain name spatiotemporal dynamic relationship graph with timestamp.
4. The method according to claim 3, characterized in that: The process of convolving the spatiotemporal dynamic relationship graph of the domain name through the spatiotemporal graph neural network model to obtain the spatiotemporal dynamic features of the domain name includes the following steps: Obtaining a node feature matrix according to the domain name spatiotemporal dynamic relationship diagram; Performing graph convolution on the node feature matrix at each time step through a graph convolution weight matrix to obtain node spatial features; Based on a preset step size range, the node feature matrix of different time steps is subjected to time series convolution by a time series convolution weight matrix to obtain node time series features; Fusion of the node spatial features and the node temporal features to obtain fusion features; The fused features are used through an activation function to generate an updated node feature matrix, and the updated node feature matrix is used as the spatiotemporal dynamic features of the domain name.
5. The method according to claim 1, characterized in that The method of converting the malicious domain name detection task into a plurality of meta-learning tasks by adopting a meta-learning strategy, and modeling the similarities between the meta-learning tasks based on Gaussian process according to the spatiotemporal dynamic characteristics, includes the following steps: Defining a number of meta-learning tasks according to the malicious domain name detection task, wherein each of the meta-learning tasks corresponds to the domain name relationship in a different time period; Aggregating the spatiotemporal dynamic features of the same time period to obtain a task feature vector for each meta-learning task; The similarity between the tasks is obtained according to the Euclidean distance of the task feature vectors between the meta-learning tasks.
6. The method according to claim 1, characterized in that The step of optimizing the inner and outer layers of the spatiotemporal graph neural network model according to the similarity includes the following steps: The inner layer of the spatiotemporal graph neural network model is optimized with the goal of minimizing the loss function of the current task, and the time step parameter is updated according to the similarity by a gradient descent algorithm; The spatiotemporal graph neural network model is outer-optimized with the goal of minimizing the loss functions on multiple tasks, and the meta-learning parameters are updated according to the similarity through a gradient descent algorithm.
7. The method according to claim 1, characterized in that The method further comprises the following steps: Obtaining a true label of the predicted label; Determine a parameter gradient according to the predicted label and the true label; Normalizing the parameter gradient to obtain the task importance weight; Update the model parameters of the spatiotemporal graph neural network model according to the task importance weights.
8. A malicious domain name detection device, characterized in that: The device comprises: The first module is used to obtain domain name feature data and pre-process the domain name feature data to obtain a training data set; The second module is used to construct a domain name spatiotemporal dynamic relationship graph with timestamps based on the training data set and the domain name relationships between the domain names; The third module is used to convolve the spatiotemporal dynamic relationship graph of the domain name through a spatiotemporal graph neural network model to obtain the spatiotemporal dynamic features of the domain name; The fourth module is used to transform the malicious domain name detection task into a plurality of meta-learning tasks by adopting a meta-learning strategy, and to model the similarities between the meta-learning tasks based on a Gaussian process according to the spatiotemporal dynamic characteristics; The fifth module optimizes the inner and outer layers of the spatiotemporal graph neural network model according to the similarity; The sixth module inputs the domain name to be detected into the optimized spatiotemporal graph neural network model to obtain a predicted label.
9. An electronic device, characterized in that: The electronic device comprises a memory and a processor, the memory stores a computer program, and the processor implements the method according to any one of claims 1 to 7 when executing the computer program.
10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.
Citation Information
Cited By
Encrypted traffic analysis method based on interaction spatio-temporal characteristics
CN120378219A