Domain name information processing and displaying method based on multi-modal data fusion

Through multimodal data fusion and Tab Net model combined with dragonfly optimization algorithm, the problem of multimodal data fusion in domain name risk identification is solved, and high accuracy and interpretability risk identification and display are achieved.

CN120342997AActive Publication Date: 2025-07-18HEFEI XUNYUN NETWORK TECH CO LTD

Patent Information

Application Number
CN202510619079.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-14
Publication Date
2025-07-18
Estimated Expiration
2045-05-14

AI Technical Summary

Technical Problem

The prior art lacks the ability to effectively integrate and model multimodal data in domain name risk identification, resulting in low recognition accuracy, weak generalization ability, and lack of interpretability and visual display ability.

Method used

The multimodal data fusion method is adopted to integrate the feature embedding of structured registration information, WHOIS text, DNS analytical behavior and web page images with Z-score, combined with the Tab Net deep feature screening model and dragonfly optimization algorithm for risk prediction, and an interactive knowledge graph display structure is constructed.

Benefits of technology

It improves the accuracy of domain name risk identification and model adaptability, enhances the interpretability and visual analysis capabilities of the results, and achieves efficient risk identification and display.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342997A_ABST
    Figure CN120342997A_ABST
Patent Text Reader

Abstract

The invention discloses a domain name information processing and displaying method based on multi-modal data fusion, and the method comprises the following steps: S1, collecting and preprocessing domain name multi-modal original data, and generating a preprocessed data sample set; s2, performing feature extraction on the preprocessed data sample set, and constructing a multi-modal fusion feature vector sequence; s3, constructing an initial Tab Net model, and outputting an initial domain name risk prediction result; s4, constructing a model performance evaluation objective function; s5, introducing a dragonfly optimization algorithm, and searching to obtain an optimal Tab Net parameter combination; and S6, based on the optimal Tab Net parameter combination, obtaining an optimized Tab Net model, and outputting a final domain name risk prediction result. And S7, based on the final domain name risk prediction result, constructing a domain name knowledge graph display structure, and generating an interactive graph display result. According to the method, a multi-modal feature extraction mechanism, a Tab Net depth model and a dragonfly optimization algorithm are fused, and intelligent prediction of domain name risks and interactive knowledge graph display optimization are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data intelligent processing and information security, and particularly relates to a method for processing and displaying domain name information based on multi-modal data fusion. Background Art

[0002] With the rapid development of Internet infrastructure and the continuous expansion of network application ecosystems, domain names, as the key entry point for accessing Internet resources, have gradually become important objects for network space governance, information security supervision, and malicious behavior identification. Especially in the context of increasingly complex network threats such as cyber attacks, phishing websites, malicious redirection, and botnets, how to effectively identify high-risk domain names and improve the interpretability and visualization level of domain name resolution behavior has become a research hotspot in the field of information security. Traditional domain name information processing methods mainly rely on rule matching or static black and white list comparison of structured registration information (such as registrants, registrars, registration times, etc.). Although these methods are simple to implement, they lack the ability to deeply model unstructured information (such as WHOIS text), behavioral data (such as DNS resolution behavior, access logs), and visual content (such as web page images), and cannot comprehensively characterize the risk characteristics of domain names under multi-dimensional information, resulting in detection results being easily affected by evasion strategies and weak generalization ability.

[0003] In recent years, driven by the development of artificial intelligence and big data analysis methods, more and more research has attempted to apply machine learning models to domain name risk identification tasks. For example, traditional models such as decision trees, support vector machines, and random forests are used to classify and train the characteristics of domain names; or deep learning architectures are introduced to extract deep characteristics of domain name behavior through methods such as multi-layer perceptrons and convolutional neural networks. However, these methods usually only process structured or text single-modal data, lack a mechanism for fusing and modeling different data types, and are difficult to effectively integrate modal information such as images, access behaviors, and time series, resulting in limited recognition accuracy.

[0004] In addition, in terms of multi-modal data processing, existing methods mostly use simple splicing or independent modeling methods to combine various features, lacking a unified feature encoding and fusion framework. For example, some research directly sends the concatenated input vector of text encoding results and structured numerical values into a neural network without effectively screening and weight assignment for the importance differences and feature redundancies between modalities, resulting in unstable training processes and poor convergence effects. In the process of feature fusion, there are problems such as uneven dimensions, semantic differences, and noise pollution between modalities. If no standardization processing and feature importance screening are performed, it is easy to cause overfitting or information loss, reducing the generalization ability and practical usability of the model.

[0005] In terms of modeling algorithms, although the Tab Net model has been proposed and widely used in structured data scenarios in recent years, it has performed well in the fields of medicine, finance, risk control, etc. due to its advantages such as feature mask generation and sparse attention mechanism. However, there is still a lack of in-depth application research on the use of Tab Net for fusing multimodal features, especially in combination with domain name scenarios, in the public literature. The structural characteristics of Tab Net, such as serial decision steps, multi-step feature screening and context accumulation mechanism, provide a good foundation for building classifiers with strong interpretability and adaptive feature selection. However, if it is directly applied to fusion scenarios containing heterogeneous data such as text, images, and behaviors, the model structure needs to be readjusted and the weight distribution mechanism needs to be redesigned in combination with modal attributes. Existing technologies have not yet conducted in-depth exploration of this.

[0006] In terms of model performance optimization, current mainstream optimization methods such as grid search, random search, Bayesian optimization, etc. are usually only applicable to model environments with small parameter space and strong task stability. For deep structures such as Tab Net with multiple important hyperparameters (such as learning rate, mask dimension, decision steps, sparse coefficient, etc.), there are complex interactions between the hyperparameters. Traditional optimization methods face problems such as low search efficiency and easy to fall into local optimality. Intelligent optimization algorithms that have emerged in recent years, such as particle swarm optimization, genetic algorithm, firefly algorithm, etc., have certain global search capabilities, but still have shortcomings in convergence speed and adaptability. As an intelligent optimization method inspired by group behavior, the dragonfly optimization algorithm simulates the five behavioral mechanisms of dragonfly groups (separation, arrangement, attraction, food guidance, enemy avoidance), has the advantages of strong global search capabilities and good local fine adjustment capabilities, and has the potential to search for optimal solutions in high-dimensional nonlinear space. However, there is no public literature that deeply integrates it with the Tab Net model for multimodal risk modeling tasks.

[0007] In terms of display and explainability, existing domain name risk identification systems are usually based on text reports or static label outputs, lacking the ability to display interactive graphs, making it difficult for security personnel to conduct in-depth tracing or relationship analysis of identification results. Although some studies have introduced knowledge graph methods to model domain name-related entities, they mostly focus on entity extraction and triple construction, and are not linked to risk prediction results, and cannot intuitively reflect "where the risk comes from and what kind of behavior it stems from." In addition, the graph construction granularity, edge type design, node weight mapping, etc. lack detailed logic, and fail to be customized for specific needs in domain name security scenarios, making it difficult to meet the high requirements for explainability and visualization in actual combat scenarios. .

[0008] Therefore, how to provide a domain name information processing and display method based on multimodal data fusion is a problem that technical personnel in this field urgently need to solve. Summary of the invention

[0009] An object of the present invention is to propose a method for processing and displaying domain name information based on multi-modal data fusion. The present invention fully fuses multi-source heterogeneous data such as structured registration information, WHOIS text, DNS resolution behavior, access logs, and web page images, adopts feature embedding, modality standardization, and Z-score fusion mechanisms, combines the Tab Net deep feature screening model and the dragonfly optimization algorithm for risk prediction modeling and parameter adaptive tuning, and constructs an interactive domain name knowledge graph display structure, which has the advantages of high risk identification accuracy, strong model adaptation ability, and strong interpretability of display results.

[0010] A method for processing and displaying domain name information based on multi-modal data fusion according to an embodiment of the present invention includes the following steps:

[0011] S1. Collect multi-modal original data of domain names and perform preprocessing to generate a preprocessed data sample set;

[0012] S2. Extract features from the preprocessed data sample set to construct a multi-modal fusion feature vector sequence;

[0013] S3. Construct an initial Tab Net model, construct a saliency screening mask for the input multi-modal feature vector sequence, apply attention weighting to the activated fusion features, and output an initial domain name risk prediction result;

[0014] S4. Based on the initial domain name risk prediction result, construct a model performance evaluation objective function;

[0015] S5. Introduce the dragonfly optimization algorithm, initialize the dragonfly individual population, each individual in the population represents a set of Tab Net hyperparameter combinations, and search for the optimal Tab Net parameter combination according to the classification performance feedback by the initial domain name risk prediction result;

[0016] S6. Based on the optimal Tab Net parameter combination, obtain an optimized Tab Net model and output a final domain name risk prediction result;

[0017] S7. Based on the final domain name risk prediction result, construct a domain name knowledge graph display structure and generate an interactive graph display result.

[0018] Optionally, the preprocessed data sample set includes structured registration information fields after format uniform processing, WHOIS text fields after null value cleaning, DNS resolution record data after noise filtering and timestamp regularization processing, original access log behavior fields after normalization, and web page image data after size regularization and unified encoding format conversion;

[0019] The structured registration information fields include domain name, registration time, registrar, registration duration, privacy protection flag, DNS record type, resolution status code, and registration status code;

[0020] The WHOIS text field coding information includes the encoded results of the name of the registrant, registration email, registration agency, and address information text content after word segmentation and embedding processing;

[0021] The DNS resolution record data includes resolution time, resolution type, TTL value, resolved result IP, and response status code.

[0022] Optionally, S2 specifically represents:

[0023] S21. Numerically encode the structured registration information fields, map the registration time, registration duration, registration status, and DNS record type to numerical features according to the field type, and generate a structured feature matrix;

[0024] S22. Use the bag-of-words model to perform word frequency encoding on the WHOIS text fields and construct a term-sample sparse matrix;

[0025] S23. Calculate the behavioral statistical features of the DNS resolution record data, including query frequency, average TTL, IP change times, and abnormal response rate, and generate a behavioral feature matrix;

[0026] S24. Extract behavioral vectors from the access log record fields, including the number of accesses per unit time, the number of source IPs, and the dispersion of access times, and construct an access behavior feature matrix;

[0027] S25. Use an image embedding model to extract image representations from the web page image data and generate an image feature matrix;

[0028] S26. Concatenate the structured feature matrix, term-sample sparse matrix, behavioral feature matrix, access behavior feature matrix, and image feature matrix by column to form a fused feature matrix. Perform standardization processing on the fused feature matrix, and use the Z-score standardization method to convert each column of features into a standard normal distribution with a mean of 0 and a variance of 1 to obtain the multi-modal fused feature vector sequence X.

[0029] Optionally, S3 specifically represents:

[0030] S31. Define the initial Tab Net model structure, including an input layer, a feature transformation and encoding layer, multiple cascaded decision step modules, a feature mask generation module, a sparse attention mechanism module, an information accumulation module, and an output layer. Connect each module layer by layer to construct a complete structure;

[0031] S32. Initialize the model input layer and set the input data as the multi-modal fusion feature vector sequence X;

[0032] S33. Construct the feature transformation encoding layer, and map the input multi-modal fusion feature vector sequence X to the latent space through the shared fully connected sub-network FC e to generate the encoding matrix E;

[0033] S34. Set up L concatenated decision step modules, perform weighted fusion operations on the outputs of all decision steps, and obtain the final representation matrix;

[0034] S35. Construct the output layer structure, perform forward prediction on the final representation matrix, and output the initial domain name risk prediction result, where the initial domain name risk prediction result includes the domain name risk classification label vector, risk score vector, and feature importance vector.

[0035] Optionally, S34 is specifically expressed as:

[0036] S341. Receive the previous layer's progressive representation and the multi-modal fusion feature vector sequence X, and output the current step's feature mask matrix M through the modality-aware feature mask generation module (l) ;

[0037] S342. Perform element-wise multiplication on the generated feature mask matrix M (l) and the multi-modal fusion feature vector sequence X to form the current step's activated modality features;

[0038] S343. Input the current step's activated modality features into the decision step feature transformation network, adopt a non-shared network structure specialized for the domain name scenario, perform independent mappings on the structured field, WHOIS text field, and DNS behavior field respectively and then merge them to construct the current step's embedded feature representation:

[0039]

[0040] where, H (l) is the feature embedding representation of the first decision step, Concat(·) is the vector concatenation operation, W s is the structured feature transformation weight matrix, is the activated feature sub-vector of the structured modality in the current decision step, W t is the text feature transformation weight matrix, is the activated feature sub-vector of the text modality in the current decision step, W b is the behavior feature transformation weight matrix, is the activated feature sub-vector of the behavior modality in the current decision step;

[0041] S344. Embed the current step's feature representation into the sparse attention mechanism module to construct a cross-modal association channel, identify combined risks, and output a context-enhanced representation;

[0042] S345. Perform weighted fusion on the context-enhanced representation and the previous step's progressive representation to form the current step's progressive representation, and perform concatenation or weighted fusion operations on the progressive representations output by the decision steps to obtain the final representation matrix.

[0043] Optionally, S4 specifically represents:

[0044] S41. Extract the risk classification label results from the initial domain name risk prediction results, and calculate the classification performance metrics based on the risk classification label results and the true labels:

[0045]

[0046] Among them, represents the classification performance loss term, n represents the total number of domain name samples to be processed in the input batch, i represents the domain name sample index, C represents the total number of domain name risk classifications, c represents the domain name risk classification index, w c is the class weight, y i represents the true label of the i-th sample, and p i,c represents the probability that the i-th sample is predicted to be the c-th class;

[0047] S42. Construct an index for the complexity of the model structure:

[0048]

[0049] Among them, represents the model complexity loss term, α1 represents the parameter regularization coefficient, L represents the total number of decision steps, 1 represents the decision step index, represents the first-layer weight matrix in the first decision step, and α2 represents the layer depth penalty coefficient;

[0050] S43. Construct an index for feature sparsity:

[0051]

[0052] Among them, represents the feature sparsity loss term, ω is the importance weight vector of the input features, and ||||1 represents the sum of the absolute values of all elements in the vector;

[0053] S44. Combine and construct the objective function for evaluating the model performance:

[0054]

[0055] Among them, J is the objective function for model performance evaluation, λ1 is the weight coefficient of the classification loss, λ2 is the weight coefficient of the model complexity loss, and λ3 is the weight coefficient of the feature sparsity loss.

[0056] Optionally, the true label includes three-category label results generated by comprehensively judging multi-dimensional features such as the integrity and credibility of the registration information combined with the domain name, the frequency and stability of DNS resolution behavior, and abnormal request patterns in access logs through a preset rule system.

[0057] Optionally, the S5 specifically represents:

[0058] S51. Set the objective function of the dragonfly optimization algorithm as the model performance evaluation objective function J, and initialize the dragonfly individual population. The position vector P of each individual in the population i represents a set of Tab Net hyperparameter combinations to be optimized;

[0059] S52. Construct an interaction model between population individuals. In each iteration, for each dragonfly individual i, calculate the update vector according to the following five behavior mechanisms:

[0060]

[0061] Among them, is the update vector of the i-th dragonfly individual in the current iteration, s is the weight factor of the separation behavior, represents the average reverse distance vector between the dragonfly individual i and its neighbors, a is the weight factor of the alignment behavior, represents the directional relationship between the individual i and the center of its neighbors, c is the weight factor of the attraction behavior, represents the moving direction of the individual approaching the center of the neighbor group, f is the weight factor of the food source guidance, represents the food source guidance vector, e is the weight factor of the enemy avoidance behavior, represents the direction in which the individual evacuates from the area with poor current evaluation effect, ω is the inertia factor, represents the historical direction inertia, and t represents the current iteration round number;

[0062] S53. Update the individual position according to the update vector to obtain a new parameter combination, and use it to train the initial TabNet model to obtain the risk prediction result under the current combination, and calculate the corresponding performance evaluation value;

[0063] S54. In each iteration, sort the objective function values of all dragonfly individuals, update the optimal individual position of the current population, and use it as the food source guidance vector for the next iteration;

[0064] S55. Terminate the search when the global optimal solution convergence condition is met, and output the optimal parameter combination P* , the optimal parameter combination P * includes the optimal learning rate, the optimal mask dimension, the optimal number of decision steps, the optimal attention mechanism configuration, and the optimal regularization coefficient.

[0065] Optionally, S6 specifically represents:[[]]

[0066] S61. Receive the optimal parameter combination P output by the dragonfly optimization algorithm * ;

[0067] S62. Based on the optimal parameter combination P * Set the learning rate, feature mask dimension, number of decision steps, hidden layer dimension, and weighted coefficient of the performance objective function of the Tab Net model to obtain an optimized Tab Net model;

[0068] S63. Input the multi-modal fusion feature vector sequence X into the optimized Tab Net model, and perform multi-step feature mask generation, modal feature transformation, attention enhancement, and state accumulation operations to obtain the final output representation;

[0069] S64. Generate the final risk prediction result based on the output representation, and the final risk prediction result includes the domain name risk classification label, the domain name risk score value, and the feature importance weight vector.

[0070] Optionally, S7 specifically represents:[[]]

[0071] S71. Correspondingly integrate the final risk prediction result with the structured registration information, WHOIS text fields, DNS resolution records, and access log fields;

[0072] S72. Construct a graph node set, and the node set includes domain name entity nodes, registrant name nodes, IP address nodes, DNS resolution behavior nodes, and risk label nodes, and each type of node has a unique identifier and attribute fields;

[0073] S73. Construct a graph edge set, and the edge set includes the "registered at" edge between the registrant name and the domain name, the "resolved to" edge between the domain name and the IP address, the "access source" edge between the IP address and the DNS behavior, the "associated label" edge between the domain name and the risk label, and the "triggered by feature" edge between the feature field and the risk label;

[0074] S74. Set the domain name risk score value as the visible weight parameter of the domain name entity node, and set the node color type according to the domain name risk classification label, where the normal class corresponds to green, the malicious class corresponds to red, and the suspected class corresponds to yellow;

[0075] S75. Visualize and arrange the above nodes and edges using a graph layout method based on the force-directed algorithm to generate an interactive atlas display interface. The interface supports clicking on nodes to view detailed structured registration information, WHOIS fields, DNS behavior logs, and triggered risk characteristics.

[0076] The beneficial effects of the present invention are as follows:

[0077] First, different from the existing domain name information processing methods that usually rely only on structured registration information or single-modal data for static analysis, the present invention proposes a domain name information processing and display method based on multi-modal data fusion. Through the joint modeling of five modalities, namely structured registration information, WHOIS text, DNS behavior logs, access behavior, and web page images, the semantic features and behavior patterns of domain names in different dimensions are fully explored. By encoding, normalizing, and constructing feature vectors for each type of modal data, and using the Z-score method to uniformly fuse them into a standard input matrix, the problems of inconsistent dimensions, inconsistent distributions, and misaligned semantics among multi-source heterogeneous data are effectively solved, significantly improving the feature representation ability and model generalization performance. Compared with the traditional recognition methods that only rely on structured features or static rules for judgment, the present invention can comprehensively evaluate the risk characteristics of domain names from multiple perspectives and modalities, with higher coverage and stronger robustness.

[0078] Second, in terms of constructing the risk prediction model, the present invention innovatively introduces the Tab Net deep structure as the main architecture for multi-modal feature modeling, and combines a modal-aware feature mask, a sparse attention mechanism, and a progressive decision-making step optimization process to achieve adaptive selection and context-enhanced expression of different modal features. Through the non-shared sub-network structure specialized for the domain name scenario, the structured fields, text fields, and behavior fields are respectively embedded and represented, effectively improving the model's ability to perceive modal semantic differences. The sparse attention mechanism guides the model to focus on high-weight combined features, avoiding redundant interference and improving the model training efficiency and interpretability. Compared with the existing general deep learning models that directly splice inputs or share parameters for training, the present invention introduces a modal difference perception mechanism at the structural design level, further improving the accuracy and interpretability of domain name risk recognition.

[0079] Thirdly, in terms of model optimization, the present invention first deeply integrates the dragonfly optimization algorithm with the Tab Net model, constructs a high-dimensional parameter search space driven by the individual behavior of dragonflies, and combines the domain name risk prediction task to construct a triple objective function of classification accuracy, model complexity, and feature sparsity, comprehensively guiding the search and optimization of the parameter space. The dragonfly algorithm can effectively jump out of the local optimal trap and quickly obtain the optimal hyperparameter combination suitable for different task scenarios by simulating five behavioral mechanisms of group separation, alignment, attraction, food guidance, and enemy avoidance, with significant global search and local convergence capabilities. Compared with traditional grid search or genetic algorithms, it has higher optimization efficiency and more stable convergence. Combining the structural characteristics of the Tab Net model, the present invention improves the model prediction accuracy and training robustness through an intelligent optimization process, significantly enhancing the adaptability of the system in a complex dynamic data environment.

[0080] In terms of display and interaction analysis, the present invention constructs an interactive knowledge graph display structure centered on the risk prediction results. For the first time, five types of nodes, namely domain name entities, registration information, IP behavior, access logs, and risk labels, and their associated edges are constructed in the form of a graph to form a visual expression of the full life cycle data of domain names. By introducing color mapping, visual weights of risk scores, and multi-edge type design, the expressiveness and information traceability of the graph structure are improved. Users can quickly view the registrant information, DNS behavior, access sources, and key features triggering risks corresponding to domain names by clicking on the graph nodes, improving the analysis efficiency and decision-making accuracy. Compared with the traditional static table output method, the graph interaction mechanism provided by the present invention enhances the interpretability of the results while also enhancing the usability and expandability of the system in actual combat.

[0081] In addition, the overall process of the present invention realizes a closed-loop system of "multi-modal acquisition - deep fusion modeling - intelligent parameter optimization - graph visual display", with significant advantages such as a high degree of automation in the modeling process, strong recognition accuracy, and intuitive and easy-to-use display methods. Through this method, it is not only possible to effectively identify high-risk domain name behaviors such as forged domain names, phishing websites, and suspicious jumps, but also provides comprehensive and intuitive data support and decision-making basis for security operation and maintenance personnel. The overall system has extremely strong deployability, engineering feasibility, and actual combat adaptability, with broad application prospects and promotion value. Brief Description of the Drawings

[0082] The drawings are used to provide a further understanding of the present invention and constitute a part of the specification. They are used together with the embodiments of the present invention to explain the present invention and do not constitute a limitation to the present invention. In the drawings:

[0083] Figure 1 is a flowchart of a method for processing and displaying domain name information based on multi-modal data fusion proposed by the present invention;

[0084] Figure 2 This is the structural diagram of the TabNet model in a domain name information processing and display method based on multi-modal data fusion proposed by the present invention;

[0085] Figure 3 This is the optimization flow chart of optimizing the TabNet parameters by the dragonfly optimization algorithm in a domain name information processing and display method based on multi-modal data fusion proposed by the present invention. Detailed implementation manners

[0086] Now, the present invention will be further described in detail with reference to the accompanying drawings. These drawings are all simplified schematic diagrams, only illustrating the basic structure of the present invention in a schematic manner, so they only show the components related to the present invention.

[0087] Refer to Figures 1-3 , a domain name information processing and display method based on multi-modal data fusion, including the following steps:

[0088] S1. Collect the multi-modal original data of the domain name and perform preprocessing to generate a preprocessed data sample set;

[0089] S2. Extract features from the preprocessed data sample set to construct a multi-modal fusion feature vector sequence;

[0090] S3. Construct an initial TabNet model, construct a saliency screening mask for the input multi-modal feature vector sequence, apply attention weighting to the activated fusion features, and output an initial domain name risk prediction result;

[0091] S4. Based on the initial domain name risk prediction result, construct a model performance evaluation objective function;

[0092] S5. Introduce the dragonfly optimization algorithm, initialize the dragonfly individual population, each individual in the population represents a set of TabNet hyperparameter combinations, and search for the optimal TabNet parameter combination according to the classification performance feedback by the initial domain name risk prediction result;

[0093] S6. Based on the optimal TabNet parameter combination, obtain an optimized TabNet model and output a final domain name risk prediction result;

[0094] S7. Based on the final domain name risk prediction result, construct a domain name knowledge graph display structure and generate an interactive graph display result.

[0095] A domain name information processing and display method based on multi-modal data fusion provided by the present invention breaks through the limitation of traditional domain name recognition relying on single structured features and static rule judgment. By introducing a collaborative mechanism of multi-source heterogeneous data fusion, TabNet feature selection modeling, and dragonfly optimization algorithm, high-precision modeling of domain name risk recognition and adaptive optimization of the model structure are realized. Combined with an interactive knowledge graph display structure, the system not only improves the interpretability of the recognition results but also enhances the visualization analysis ability of risk association paths. This method has the advantages of high processing efficiency, strong risk recognition ability, and flexible actual combat deployment, and has broad application prospects and promotion value in network security.

[0096] In this embodiment, the preprocessed data sample set includes structured registration information fields after format unification processing, WHOIS text fields after null value cleaning, DNS resolution record data after noise filtering and timestamp regularization processing, original access log behavior fields after normalization, and web page image data after size regularization and unified encoding format conversion;

[0097] The structured registration information fields include domain name, registration time, registrar, registration duration, privacy protection flag, DNS record type, resolution status code, and registration status code;

[0098] The encoding information of the WHOIS text field includes the encoding results of the registered person's name, registered email, registered organization, and address information text content after word segmentation and embedding processing;

[0099] The DNS resolution record data includes resolution time, resolution type, TTL value, resolved result IP, and response status code.

[0100] The domain name information processing method based on multi-modal data fusion provided by the present invention breaks through the limitation of traditional methods relying only on structured fields or single data sources. By introducing preprocessing mechanisms such as format unification, noise filtering, normalization, and embedding encoding, it systematically fuses multi-modal data such as structured registration information, WHOIS text, DNS resolution records, access logs, and web page images to construct a high-quality fusion sample set. This method effectively improves the feature integrity and data consistency, provides a richer and more reliable input basis for subsequent risk recognition modeling, enhances the model expression ability while improving the recognition accuracy and processing stability, and has good adaptability and engineering practical value.

[0101] In this embodiment, S2 specifically represents:

[0102] S21. Numerically encode the structured registration information fields, map the registration time, registration duration, registration status, and DNS record type to numerical features according to the field type, and generate a structured feature matrix;

[0103] S22. Perform word frequency encoding on the WHOIS text field using the bag - of - words model to construct a term - sample sparse matrix;

[0104] S23. Calculate behavioral statistical features for DNS resolution record data, including query frequency, average TTL, number of IP changes, and abnormal response rate, and generate a behavioral feature matrix;

[0105] S24. Extract behavioral vectors from the access log record fields, including the number of accesses per unit time, the number of source IPs, and the dispersion of access times, and construct an access behavior feature matrix;

[0106] S25. Use an image embedding model to extract image representations from web page image data and generate an image feature matrix;

[0107] S26. Concatenate the structured feature matrix, term - sample sparse matrix, behavioral feature matrix, access behavior feature matrix, and image feature matrix by column to form a fused feature matrix. Perform standardization processing on the fused feature matrix. Use the Z - score standardization method to transform each column of features into a standard normal distribution with a mean of 0 and a variance of 1 to obtain a multi - modal fused feature vector sequence X.

[0108] The present invention constructs a multi - modal extraction mechanism for four types of features, namely structured, text, behavior, and image, to fully exploit the deep information structure of domain name registration, resolution, access, and web page content. Generate high - dimensional feature matrices through numerical mapping, bag - of - words encoding, statistic extraction, and image embedding, and perform unified processing using the Z - score standardization method, effectively solving the problems of data distribution differences and scale inconsistencies between modalities. The fused vector sequence after splicing multi - source features has higher information density and representation ability, providing a robust, standard, and scalable input basis for subsequent risk prediction models, significantly improving the accuracy, stability, and generalization performance of the models, and having good practical application value.

[0109] In this embodiment, S3 specifically represents:

[0110] S31. Define the initial Tab Net model structure, including an input layer, a feature transformation encoding layer, multiple cascaded decision step modules, a feature mask generation module, a sparse attention mechanism module, an information accumulation module, and an output layer. Connect each module layer - by - layer to construct a complete structure;

[0111] S32. Initialize the model input layer and set the input data as the multi - modal fused feature vector sequence X;

[0112] S33. Construct the feature transformation encoding layer through a shared fully - connected sub - network FC eMap the input multi-modal fusion feature vector sequence X to the latent space to generate the encoding matrix E;

[0113] S34. Set up L cascaded decision step modules, perform a weighted fusion operation on the outputs of all decision steps to obtain the final representation matrix;

[0114] S35. Construct an output layer structure, perform forward prediction on the final representation matrix, and output the initial domain name risk prediction result, where the initial domain name risk prediction result includes a domain name risk classification label vector, a risk score vector, and a feature importance vector.

[0115] In the present invention, by introducing a structured Tab Net model architecture, deep modeling of multi-modal fusion features and adaptive screening of feature importance are realized. The model includes an input layer, a feature transformation and encoding layer, a cascaded decision step module, a feature mask generation and sparse attention mechanism module, which can dynamically select key feature regions during the training process and effectively suppress the interference of redundant information. The information accumulation mechanism further improves the model's ability to express complex patterns. Finally, a risk classification label, a score value, and a feature importance vector are output, realizing high-precision and highly interpretable risk prediction. This structure has the advantages of end-to-end training ability, strong scalability, high convergence efficiency, etc., significantly improving the intelligence and practicality of domain name risk modeling.

[0116] In this embodiment, S34 specifically represents:

[0117] S341. Receive the previous progressive representation and the multi-modal fusion feature vector sequence X, and output the current step feature mask matrix M through the modality-aware feature mask generation module (l) ;

[0118] S342. Perform an element-wise multiplication on the generated feature mask matrix M (l) and the multi-modal fusion feature vector sequence X to form the current step activated modal features;

[0119] S343. Input the current step activated modal features into the decision step feature transformation network, adopt a non-shared network structure specialized for the domain name scenario, perform independent mappings on the structured field, WHOIS text field, and DNS behavior field respectively and then merge them to construct the current step embedded feature representation:

[0120]

[0121] where, H (l) is the feature embedding representation of the l-th decision step, Concat(·) is a vector concatenation operation, W s is the structured feature transformation weight matrix, is the activated feature sub-vector of the structured modality in the current decision step, Wt is the weight matrix for text feature transformation, is the activated feature sub-vector of the text modality in the current decision step, W b is the weight matrix for behavior feature transformation, is the activated feature sub-vector of the behavior modality in the current decision step;

[0122] S344. Input the embedding feature representation of the current step into the sparse attention mechanism module, construct a cross-modal association channel, identify combined risks, and output a context-enhanced representation;

[0123] S345. Perform weighted fusion on the context-enhanced representation and the progressive representation of the previous layer to form the progressive representation of the current step, and perform concatenation or weighted fusion operations on the progressive representations output by the decision steps to obtain the final representation matrix.

[0124] By introducing a modality-aware feature mask and a non-shared network structure, the present invention enhances the discrimination ability and expression accuracy of the Tab Net model for multi-modal features. In each decision step, key modality features are dynamically activated through a mask mechanism, and independent modeling is performed in combination with structured, text, and behavior sub-networks respectively, realizing precise capture of different data semantics. The sparse attention mechanism further constructs cross-modal associations, identifies potential combined risk factors, and improves the modeling depth of the model for complex risk features. The context enhancement and progressive fusion strategy enables the representation to be progressively optimized between levels, and finally constructs a representation matrix with high information density, significantly improving the accuracy and interpretability of risk identification, and having good practical value and scalability.

[0125] In this embodiment, S4 is specifically represented as:

[0126] S41. Extract the risk classification label results in the initial domain name risk prediction results, and calculate classification performance metrics based on the risk classification label results and the true labels:

[0127]

[0128] where, represents the classification performance loss term, n represents the total number of domain name samples to be processed in the input batch, i represents the domain name sample index, c represents the total number of domain name risk classifications, c represents the domain name risk classification index, w c is the class weight, y i represents the true label of the i-th sample, p i,c represents the probability that the i-th sample is predicted to be the c-th class;

[0129] S42. Construct an index for the model structure complexity:

[0130]

[0131] Among them, represents the model complexity loss term, α1 represents the parameter regularization coefficient, L represents the total number of decision steps, 1 represents the decision step index, represents the weight matrix of the first layer in the first decision step, and α2 represents the layer depth penalty coefficient;

[0132] S43. Construct a feature sparsity index:

[0133]

[0134] Among them, represents the feature sparsity loss term, ω is the importance weight vector of the input features, and ||||1 represents the sum of the absolute values of all elements in the vector;

[0135] S44. Combine and construct a model performance evaluation objective function:

[0136]

[0137] Among them, J is the model performance evaluation objective function, λ1 is the classification loss weight coefficient, λ2 is the model complexity loss weight coefficient, and λ3 is the feature sparsity loss weight coefficient.

[0138] The present invention systematically optimizes the expression ability and structural stability of the risk prediction model by constructing a multi-dimensional model performance evaluation system including classification performance, structural complexity, and feature sparsity. Through the refined design of the classification loss function, the matching accuracy of the model to the true labels is improved; combined with the structural complexity index, regularization is introduced to control the model scale and avoid overfitting problems; at the same time, the feature sparsity index guides the model to focus on high-value features, improving the generalization ability and training efficiency. The performance evaluation function of multi-objective weighted fusion provides a scientific search basis for subsequent dragonfly optimization, enabling the model to achieve a balance among accuracy, simplicity, and interpretability, and significantly improving the overall prediction quality and system robustness.

[0139] In this embodiment, the true labels include three-category label results generated by comprehensively judging through a preset rule system based on multi-dimensional features such as the integrity and credibility of the registration information of the combined domain name, the frequency and stability of DNS resolution behavior, and the abnormal request patterns in the access logs.

[0140] The present invention effectively improves the credibility and discrimination of the training data by introducing a true label construction mechanism that combines registration information, resolution behavior, and access log features, and generating three-category label results using a rule system, provides a higher-quality supervision signal for model learning, and enhances the accuracy and stability of risk identification.

[0141] In this embodiment, the specific representation of S5 is:

[0142] S51. Set the objective function of the dragonfly optimization algorithm as the model performance evaluation objective function J, and initialize the dragonfly individual population. The position vector P of each individual in the population i represents a set of Tab Net hyperparameter combinations to be optimized;

[0143] S52. Construct an interaction model between population individuals. In each iteration, for each dragonfly individual i, calculate the update vector according to the following five behavioral mechanisms:

[0144]

[0145] where, is the update vector of the i-th dragonfly individual in the current iteration, s is the weight factor of the separation behavior, represents the average reverse distance vector between the dragonfly individual i and its neighbors, a is the weight factor of the alignment behavior, represents the directional relationship between the individual i and the center of its neighbors, c is the weight factor of the attraction behavior, represents the moving direction of the individual approaching the center of the neighbor group, f is the weight factor of the food source guidance, represents the food source guidance vector, e is the weight factor of the enemy avoidance behavior, represents the direction for the individual to withdraw from the area with poor current evaluation effect, ω is the inertia factor, represents the historical direction inertia, and t represents the current iteration round number;

[0146] S53. Update the individual position according to the update vector to obtain a new parameter combination, and use it to train the initial TabNet model to obtain the risk prediction result under the current combination, and calculate the corresponding performance evaluation value;

[0147] S54. In each iteration, sort the objective function values of all dragonfly individuals, update the optimal individual position of the current population, and use it as the food source guidance vector for the next iteration;

[0148] S55. Terminate the search when the global optimal solution convergence condition is met, and output the optimal parameter combination P * The optimal parameter combination P * includes the optimal learning rate, the optimal mask dimension, the optimal decision-making step number, the optimal attention mechanism configuration, and the optimal regularization coefficient.

[0149] In the present invention, the dragonfly optimization algorithm is introduced to adaptively search for the key hyperparameters of the Tab Net model, and an optimization function targeting classification performance, model complexity, and feature sparsity is constructed to systematically improve the model prediction effect and structural rationality. The dragonfly algorithm simulates five group behaviors among individuals, namely separation, alignment, attraction, food guidance, and enemy avoidance, dynamically updates the parameter combination, and has the advantages of strong global search ability and high local fine-tuning ability. By screening the optimal individuals through multiple rounds of iteration and guiding the subsequent search direction, it effectively overcomes the limitations of traditional grid search and genetic algorithms in high-dimensional parameter spaces, significantly improves the model training efficiency and final performance, and enhances the robustness and adaptability of the system in complex environments.

[0150] In this embodiment, S6 specifically represents:

[0151] S61. Receive the optimal parameter combination P output by the dragonfly optimization algorithm * ;

[0152] S62. Based on the optimal parameter combination P * Set the learning rate, feature mask dimension, decision-making steps, hidden layer dimension, and weighted coefficients of the performance objective function of the Tab Net model to obtain an optimized Tab Net model;

[0153] S63. Input the multi-modal fusion feature vector sequence X into the optimized Tab Net model, and perform multi-step feature mask generation, modal feature transformation, attention enhancement, and state accumulation operations to obtain the final output representation;

[0154] S64. Generate the final risk prediction result based on the output representation, and the final risk prediction result includes a domain name risk classification label, a domain name risk score value, and a feature importance weight vector.

[0155] In the present invention, by receiving the optimal hyperparameter combination output by the dragonfly optimization algorithm, fine configuration of core parameters such as the learning rate, mask dimension, and decision-making steps of the Tab Net model is carried out to construct a risk prediction model with optimal performance. The optimized model combines multi-step mask generation, modal feature transformation, sparse attention, and state accumulation mechanisms, and can accurately model the deep interaction relationships between multi-modal features, enhancing the model's expression ability for complex domain name behavior features. The finally generated risk classification label, score value, and feature importance weight not only improve the prediction accuracy and stability, but also provide a solid foundation for subsequent result interpretability analysis and atlas display, significantly enhancing the practical value and deployment effect of the system.

[0156] In this embodiment, S7 specifically represents:

[0157] S71. Integrate the final risk prediction results with structured registration information, WHOIS text fields, DNS resolution records, and access log fields.

[0158] S72. Construct a graph node set, where the node set includes domain name entity nodes, registrant name nodes, IP address nodes, DNS resolution behavior nodes, and risk label nodes. Each type of node has a unique identifier and an attribute field.

[0159] S73. Construct a graph edge set, where the edge set includes a "registered in" edge between the registrant name and the domain name, a "resolved to" edge between the domain name and the IP address, an "access source" edge between the IP address and the DNS behavior, an "associated label" edge between the domain name and the risk label, and a "triggered by feature" edge between the feature field and the risk label.

[0160] S74. Set the domain name risk score value as the visual weight parameter of the domain name entity node, and set the node color type according to the domain name risk classification label. Among them, the normal class corresponds to green, the malicious class corresponds to red, and the suspected class corresponds to yellow.

[0161] S75. Use a graph layout method based on the force-directed algorithm to visually arrange the above nodes and edges, generate an interactive graph display interface, and the interface supports clicking on nodes to view the detailed content of structured registration information, WHOIS fields, DNS behavior logs, and triggered risk features.

[0162] Through constructing a knowledge graph display structure based on the domain name risk prediction results, the present invention realizes the visual expression of data analysis results and interactive traceability. The system constructs domain names, registrants, IP addresses, DNS behaviors, and risk labels into graph nodes, and connects various entities with semantic edges to clearly display the association path between domain name behaviors and risks. The risk levels are distinguished by node colors, the node weights are set by score values, and an intuitive graph view is generated by combining the force-directed layout algorithm. Users can click on nodes to view detailed feature and log information, significantly improving the interpretability of model outputs and the research and judgment efficiency, and enhancing the practicality, transparency, and security response capabilities of the system.

[0163] Example 1:

[0164] To verify the feasibility of the present invention in implementation, the present invention is applied to the intelligent upgrade project of a network security data analysis system. The goal is to perform risk identification, behavior analysis, and result visualization on a large number of active domain names, and solve the problems of high difficulty in multi-modal data fusion, insufficient model identification accuracy, and lack of interpretability of results in the traditional domain name risk identification process.

[0165] The system is deployed in the monitoring environment of large backbone network data streams, and accesses multiple data sources including DNS resolution records, WHOIS registration information, user access logs, web page image snapshots, etc. The average daily access data scale reaches more than 4TB, covering millions of DNS requests, hundreds of thousands of registration fields, tens of millions of access behavior records, and hundreds of thousands of web page screenshot images. The system first encodes the structured registration information fields, such as converting registration time, registration status, etc. into numerical features; the WHOIS text is encoded into a term-sample sparse matrix through word segmentation and the TF-IDF model; behavior statistics such as query frequency, IP switching rate, response status, etc. are extracted from DNS resolution behaviors; features such as the number of accesses per unit time, the number of source IPs, and the dispersion of access time are extracted from access logs; web page images are compressed into fixed-length image vector representations through a pre-trained image embedding network.

[0166] After the above five types of modal features are uniformly processed by Z-score standardization, they are concatenated into a fusion feature matrix and used as input data to the initial Tab Net model for modeling and training. In the initial stage of training, the overall F1-score of the model is about 82%, and the determination accuracy of the "suspected risk" class is relatively low, with problems of fuzzy classification and unclear feature expression. To improve the model effect, the present invention further introduces the dragonfly optimization algorithm, and automatically optimizes multiple key hyperparameters of Tab Net by constructing a multi-objective function with classification performance, model complexity, and feature sparsity as the objectives. After more than a hundred rounds of continuous iteration in the optimization process, it finally converges to a set of optimal parameter combinations, including learning rate, mask dimension, number of decision steps, attention sparse weight, and regularization term coefficient, etc. Under this configuration, the F1-score of the optimized Tab Net model on the validation set is increased to more than 89%, and in particular, the recognition ability of the "suspected class" in the intermediate state is improved by about 8%, greatly enhancing the judgment ability of the model in scenarios with fuzzy boundaries.

[0167] To further improve the interpretability of the recognition results, the present invention constructs a knowledge graph display structure with domain names as the core at the model output stage, binds the predicted risk scores, classification labels with the corresponding trigger feature fields, and the knowledge graph also includes entity nodes such as registrant information, DNS resolution IP, access source behavior, etc. Connections are established between nodes through edge types such as "registered in", "resolved to", "access source", and "trigger risk". The system highlights high-risk domain names by linking colors with node weights, and users can deeply view the behavior tracks of domain names and their associated abnormal fields by clicking on the graph. In actual tests, through this graph structure, the operation personnel successfully located multiple domain names with abnormal scores and suspicious behavior paths, including multiple sites that redirected under false brand names, with abnormal concentration in access time distribution, frequent DNS IP switching, and highly similar web page images, which were marked with high-risk labels in the system and pushed for handling, significantly improving the efficiency of traceability and research and judgment.

[0168] To verify the recognition performance and efficiency, the method of the present invention was also compared and evaluated with the traditional random forest + multi-modal splicing method. Three rounds of parallel detections were carried out using the same data samples and evaluation label sets, and quantitative comparisons were made in multiple dimensions. The results are shown in the following table:

[0169] Table 1 Comparative effect evaluation of the method of the present invention and the traditional method in the domain name risk recognition scenario

[0170] Serial number Comparison dimension The method of the present invention Traditional method 1 Total number of domain names processed 1,000,000 1,000,000 2 Daily average processing speed (pieces) 85,000 60,000 3 F1-score (overall) 89.3% 80.7% 4 Accuracy rate 91.5% 83.2% 5 Recall rate 86.2% 78.9% 6 Malicious class recognition rate 93.1% 85.4% 7 Suspicious class recognition rate 81.4% 70.2% 8 Average processing delay (seconds) 1.83 3.97 9 Average risk score difference ±0.04 ±0.11 10 Interpretability user rating 9.1 / 10 6.8 / 10

[0171] From the comparison data in Table 1 above, it can be seen that in large-scale domain name risk recognition applications, the present invention is superior to the traditional method in terms of recognition accuracy, processing efficiency, and interpretability. Specifically, in terms of the overall recognition effect, the F1-score of the method of the present invention reaches 89.3%, an increase of nearly 9 percentage points compared with the traditional random forest method, and the accuracy rate and recall rate are also increased to 91.5% and 86.2% respectively, effectively enhancing the discrimination ability of the model in real complex scenarios, especially for the recognition of malicious and suspected domain names is more accurate and comprehensive.

[0172] In terms of processing capacity, the method of the present invention can process 85,000 domain name samples per day, an increase of more than 40% compared with the traditional method, and the average processing delay for each sample is 1.83 seconds, significantly lower than 3.97 seconds of the traditional method. This improvement in efficiency is due to the introduction of a sparse attention mechanism based on feature masking and an optimized Tab Net structure in the model structure of the present invention, which can quickly locate high-value features and reduce redundant calculations. At the same time, the dragonfly optimization algorithm is used to automatically adjust parameters, enabling the model to maintain good response speed and computational stability when processing large-scale data.

[0173] In terms of the identification of "suspected" samples, the identification rate of the present invention has been increased to 81.4%, which is more than 11% higher than that of the traditional method, effectively solving the problem of unstable classification of samples with fuzzy boundaries by the traditional method. At the same time, the present invention also constructs a knowledge graph display structure based on risk scores and trigger features. Through the visualization of node colors and risk weights, users can quickly understand the model output, improving the transparency and operability of the results. In the user satisfaction score, the interpretability score of the present invention is 9.1 points, while that of the traditional method is only 6.8 points.

[0174] In summary, while maintaining high-precision identification, the present invention achieves faster processing speed and stronger result interpretation ability, significantly improving the application effect and value of the system in actual network security scenarios.

[0175] The above is only a preferred specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, according to the technical solution of the present invention and its inventive concept, makes equivalent substitutions or changes, and should be covered by the protection scope of the present invention.

Claims

1. A method for processing and displaying domain name information based on multi-modal data fusion, characterized in that It includes the following steps: S1. Collect multi-modal original data of domain names and perform preprocessing to generate a preprocessed data sample set; S2. Extract features from the preprocessed data sample set to construct a multi-modal fusion feature vector sequence; S3. Construct an initial Tab Net model, construct a significance screening mask for the input multi-modal feature vector sequence, apply attention weighting to the activated fusion features, and output an initial domain name risk prediction result; S4. Based on the initial domain name risk prediction result, construct a model performance evaluation objective function; S5. Introduce the dragonfly optimization algorithm, initialize the dragonfly individual population, each individual in the population represents a set of Tab Net hyperparameter combinations, and search for the optimal Tab Net parameter combination according to the classification performance feedback by the initial domain name risk prediction result; S6. Based on the optimal Tab Net parameter combination, obtain an optimized Tab Net model and output a final domain name risk prediction result; S7. Based on the final domain name risk prediction result, construct a domain name knowledge graph display structure and generate an interactive graph display result.

2. The method for processing and displaying domain name information based on multi-modal data fusion according to claim 1, characterized in that, The preprocessed data sample set includes structured registration information fields after format unification processing, WHOIS text fields after null value cleaning, DNS resolution record data after noise filtering and timestamp regularization processing, original access log behavior fields after normalization, and web page image data after size regularization and unified coding format conversion; The structured registration information fields include domain name, registration time, registrar, registration duration, privacy protection flag, DNS record type, resolution status code, and registration status code; The encoding information of the WHOIS text field includes the encoding results after word segmentation and embedding processing of the registrant name, registration email, registration institution, and address information text content; The DNS resolution record data includes resolution time, resolution type, TTL value, resolved IP, and response status code.

3. A method for processing and displaying domain name information based on multimodal data fusion according to claim 1, characterized in that The specific steps of S2 include: S21. Numerically encode the structured registration information fields, map the registration time, registration duration, registration status, and DNS record type to numerical features according to the field type, and generate a structured feature matrix; S22. Use the bag-of-words model to perform word frequency encoding on the WHOIS text field to construct a term-sample sparse matrix; S23. Calculate behavioral statistical features for the DNS resolution record data, including query frequency, average TTL, IP change times, and abnormal response rate, and generate a behavioral feature matrix; S24. Extract behavioral vectors from the access log record fields, including the number of accesses per unit time, the number of source IPs, and the dispersion of access time, and construct an access behavior feature matrix; S25. Use an image embedding model to extract image representations from the web page image data and generate an image feature matrix; S26. Concatenate the structured feature matrix, term-sample sparse matrix, behavioral feature matrix, access behavior feature matrix, and image feature matrix column by column to form a fused feature matrix. Perform standardization processing on the fused feature matrix. Use the Z-score standardization method to transform each column of features into a standard normal distribution with a mean of 0 and a variance of 1, obtaining a multi-modal fused feature vector sequence X.

4. A method for processing and displaying domain name information based on multi-modal data fusion according to claim 1, characterized in that The specific steps of S3 are as follows: S31. Define the initial Tab Net model structure, including an input layer, a feature transformation encoding layer, multiple cascaded decision step modules, a feature mask generation module, a sparse attention mechanism module, an information accumulation module, and an output layer. Connect each module layer by layer to build a complete structure; S32. Initialize the input layer of the model and set the input data as the multi-modal fused feature vector sequence X; S33. Construct a feature transformation encoding layer to map the input sequence of multimodal fusion feature vectors X to the latent space through a shared fully-connected sub-network FC e to generate an encoding matrix E; S34. Set L cascaded decision step modules, perform a weighted fusion operation on the outputs of all decision steps to obtain a final representation matrix; S35. Build the output layer structure, perform forward prediction on the final representation matrix, and output the initial domain name risk prediction result, where the initial domain name risk prediction result includes a domain name risk classification label vector, a risk score vector, and a feature importance vector.

5. The method for processing and displaying domain name information based on multi-modal data fusion according to claim 4, wherein The specific steps of S34 are as follows: S341. Receive the upper-layer progressive representation and the multi-modal fusion feature vector sequence X, and output the current-step feature mask matrix M through the modality-aware feature mask generation module (l) ; S342. Perform element-wise multiplication on the generated feature mask matrix M (l) with the multi-modal fusion feature vector sequence X to form the modality features activated in the current step; S343. Input the modality features activated in the current step into the decision step feature transformation network. Use a non-shared network structure specialized for the domain name scenario to perform independent mapping and then merging on the structured fields, WHOIS text fields, and DNS behavior fields respectively, and construct the embedded feature representation of the current step: Among them, H (l) is the feature embedding representation of the first decision step, Concat(·) is the vector concatenation operation, W s is the structured feature transformation weight matrix, is the activated feature sub-vector of the structured modality in the current decision step, W t is the text feature transformation weight matrix, is the activated feature sub-vector of the text modality in the current decision step, W b is the behavior feature transformation weight matrix, is the activated feature sub-vector of the behavior modality in the current decision step; S344. Input the embedded feature representation of the current step into the sparse attention mechanism module, construct a cross-modal association channel, identify combined risks, and output a context-enhanced representation; S345. Perform weighted fusion on the context-enhanced representation and the progressive representation of the previous layer to form the progressive representation of the current step. Perform a concatenation or weighted fusion operation on the progressive representations output by the decision steps to obtain a final representation matrix.

6. A method for processing and displaying domain name information based on multi-modal data fusion according to claim 1, characterized in that The specific steps of S4 are as follows: S41. Extract the risk classification label result from the initial domain name risk prediction result, and calculate the classification performance index based on the risk classification label result and the true label; Among them, represents the classification performance loss term, n represents the total number of domain name samples to be processed in the input batch, i represents the domain name sample index, C represents the total number of classifications of domain name risks, c represents the classification index of domain name risks, w c is the class weight, y i represents the true label of the i-th sample, p i,c represents the probability that the i-th sample is predicted to be the c-th class; S42. Construct an index for the model structure complexity; Among them, represents the model complexity loss term, α1 represents the parameter regularization coefficient, L represents the total number of decision steps, 1 represents the decision step index, represents the weight matrix of the first layer in the first decision step, and α2 represents the layer depth penalty coefficient; S43. Construct an index for feature sparsity; Among them, represents the feature sparsity loss term, ω is the importance weight vector of the input features, and || ||1 represents the sum of the absolute values of all elements in the vector; S44. Combine and construct the objective function for evaluating the model performance: Where J is the objective function for evaluating the model performance, λ1 is the weight coefficient for the classification loss, λ2 is the weight coefficient for the model complexity loss, and λ3 is the weight coefficient for the feature sparsity loss.

7. A method for processing and displaying domain name information based on multi-modal data fusion according to claim 6, characterized in that, The true label includes a three-category label result generated by comprehensively judging the integrity and credibility of the domain name registration information, the frequency and stability of DNS resolution behavior, and multi-dimensional features of abnormal request patterns in access logs through a preset rule system.

8. A method for processing and displaying domain name information based on multi-modal data fusion according to claim 1, characterized in that, The specific steps of S5 are as follows: S51. Set the objective function of the dragonfly optimization algorithm as the model performance evaluation objective function J, and initialize the dragonfly individual population. The position vector P of each individual in the population i represents a set of Tab Net hyperparameter combinations to be optimized; S52. Construct an interaction model among the population individuals. In each round of iteration, calculate the update vector for each dragonfly individual i according to the following five behavioral mechanisms: Among them, is the update vector of the i-th dragonfly individual in the current iteration, s is the weight factor of the separation behavior, represents the average reverse distance vector between the dragonfly individual i and its neighbors, a is the weight factor of the alignment behavior, represents the directional relationship between the individual i and the center of its neighbors, c is the weight factor of the attraction behavior, represents the moving direction of the individual approaching the center of the neighbor group, f is the weight factor of the food source guidance, represents the food source guidance vector, e is the weight factor of the enemy avoidance behavior, represents the direction for the individual to evacuate from the area with poor current evaluation effect, ω is the inertia factor, represents the historical direction inertia, and t represents the current iteration round number; S53. Update the individual positions according to the update vector to obtain a new parameter combination, and use it to train the initial Tab Net model to obtain the risk prediction result under the current combination, and calculate the corresponding performance evaluation value; S54. In each iteration, sort the objective function values of all dragonfly individuals, update the position of the optimal individual in the current population, and use it as the food source guiding vector for the next iteration; S55. Terminate the search under the condition of satisfying the global optimal solution convergence condition, and output the optimal parameter combination P * , the optimal parameter combination P * includes the optimal learning rate, the optimal mask dimension, the optimal number of decision steps, the optimal attention mechanism configuration, and the optimal regularization coefficient.

9. A method for processing and displaying domain name information based on multi-modal data fusion according to claim 1, characterized in that, The specific steps of S6 are as follows: S61. Receive the optimal parameter combination P output by the dragonfly optimization algorithm * ; S62. Based on the optimal parameter combination P * Set the learning rate, feature mask dimension, decision-making steps, hidden layer dimension, and weighted coefficient of the performance objective function of the Tab Net model to obtain an optimized Tab Net model; S63. Input the multi-modal fusion feature vector sequence X into the optimized Tab Net model, and perform multi-step feature masking generation, modal feature transformation, attention enhancement, and state accumulation operations to obtain the final output representation; S64. Generate the final risk prediction result based on the output representation. The final risk prediction result includes the domain name risk classification label, the domain name risk score value, and the feature importance weight vector.

10. A method for processing and displaying domain name information based on multi-modal data fusion according to claim 1, characterized in that, The specific steps of S7 are as follows: S71. Correspondingly integrate the final risk prediction result with the structured registration information, WHOIS text fields, DNS resolution records, and access log fields; S72. Construct a graph node set. The node set includes domain name entity nodes, registrant name nodes, IP address nodes, DNS resolution behavior nodes, and risk label nodes. Each type of node has a unique identifier and an attribute field; S73. Construct a graph edge set. The edge set includes the "registered in" edge between the registrant name and the domain name, the "resolved to" edge between the domain name and the IP address, the "access source" edge between the IP address and the DNS behavior, the "associated label" edge between the domain name and the risk label, and the "triggered by feature" edge between the feature field and the risk label; S74. Set the domain name risk score value as the visible weight parameter of the domain name entity node, and set the node color type according to the domain name risk classification label. Among them, the normal class corresponds to green, the malicious class corresponds to red, and the suspected class corresponds to yellow; S75. Use the graph layout method based on the force-directed algorithm to visually arrange the above nodes and edges, and generate an interactive graph display interface. The interface supports clicking on nodes to view the detailed content of the structured registration information, WHOIS fields, DNS behavior logs, and triggered risk features.

Citation Information

Patent Citations

  • Overdue risk prediction method for optimizing multi-core support vector machine based on dragonfly algorithm

    CN113239638A

  • Botnet risk assessment method and device

    CN114422193A

  • Risk assessment model establishment method and device, computer equipment and storage medium

    CN116611682A

  • Risk website identification method and device, electronic equipment and storage medium

    CN117614749A

  • Multi-modal fusion feature-based phishing detection method and system

    CN119814358A

Cited By

  • Intelligent data management system

    CN120763566A

  • An intelligent data management system

    CN120763566B

  • Data sequence generation method and device, equipment and medium

    CN120932047A

  • Data sequence generation method, apparatus, device, and medium

    CN120932047B

  • Platform security intelligent supervision method and system based on data management

    CN120934860A