{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T05:03:25Z","timestamp":1782882205323,"version":"3.54.5"},"reference-count":32,"publisher":"Wiley","license":[{"start":{"date-parts":[[2021,1,18]],"date-time":"2021-01-18T00:00:00Z","timestamp":1610928000000},"content-version":"unspecified","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100010193","name":"Korea Electric Power Corporation","doi-asserted-by":"publisher","award":["R18XA05"],"award-info":[{"award-number":["R18XA05"]}],"id":[{"id":"10.13039\/501100010193","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100010193","name":"Korea Electric Power Corporation","doi-asserted-by":"publisher","award":["NRF-2019R1A2C1085311"],"award-info":[{"award-number":["NRF-2019R1A2C1085311"]}],"id":[{"id":"10.13039\/501100010193","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100003621","name":"Ministry of Science, ICT and Future Planning","doi-asserted-by":"publisher","award":["R18XA05"],"award-info":[{"award-number":["R18XA05"]}],"id":[{"id":"10.13039\/501100003621","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100003621","name":"Ministry of Science, ICT and Future Planning","doi-asserted-by":"publisher","award":["NRF-2019R1A2C1085311"],"award-info":[{"award-number":["NRF-2019R1A2C1085311"]}],"id":[{"id":"10.13039\/501100003621","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Security and Communication Networks"],"published-print":{"date-parts":[[2021,1,18]]},"abstract":"<jats:p>In recent years, cyberattacks using command and control (C&amp;C) servers have significantly increased. To hide their C&amp;C servers, attackers often use a domain generation algorithm (DGA), which automatically generates domain names for the C&amp;C servers. Accordingly, extensive research on DGA domain detection has been conducted. However, existing methods cannot accurately detect continuously generated DGA domains and can easily be evaded by an attacker. Recently, long short-term memory- (LSTM-) based deep learning models have been introduced to detect DGA domains in real time using only domain names without feature extraction or additional information. In this paper, we propose an efficient DGA domain detection method based on bidirectional LSTM (BiLSTM), which learns bidirectional information as opposed to unidirectional information learned by LSTM. We further maximize the detection performance with a convolutional neural network (CNN)\u2009+\u2009BiLSTM ensemble model using Attention mechanism, which allows the model to learn both local and global information in a domain sequence. Experimental results show that existing CNN and LSTM models achieved F1-scores of 0.9384 and 0.9597, respectively, while the proposed BiLSTM and ensemble models achieved higher F1-scores of 0.9618 and 0.9666, respectively. In addition, the ensemble model achieved the best performance for most DGA domain classes, enabling more accurate DGA domain detection than existing models.<\/jats:p>","DOI":"10.1155\/2021\/8887881","type":"journal-article","created":{"date-parts":[[2021,1,19]],"date-time":"2021-01-19T19:50:09Z","timestamp":1611085809000},"page":"1-15","source":"Crossref","is-referenced-by-count":32,"title":["Efficient Deep Learning Models for DGA Domain Detection"],"prefix":"10.1155","volume":"2021","author":[{"given":"Juhong","family":"Namgung","sequence":"first","affiliation":[{"name":"Dept. of Computer Science, Kangwon National University, Chuncheon-si, Gangwon-do 24341, Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5647-7527","authenticated-orcid":true,"given":"Siwoon","family":"Son","sequence":"additional","affiliation":[{"name":"Dept. of Computer Science, Kangwon National University, Chuncheon-si, Gangwon-do 24341, Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2396-0405","authenticated-orcid":true,"given":"Yang-Sae","family":"Moon","sequence":"additional","affiliation":[{"name":"Dept. of Computer Science, Kangwon National University, Chuncheon-si, Gangwon-do 24341, Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"311","reference":[{"key":"1","first-page":"635","article-title":"Your botnet is my botnet: analysis of a botnet takeover","author":"B. Stone-Gross"},{"key":"2","first-page":"1","article-title":"Paint it black: evaluating the effectiveness of malware blacklists","author":"M. K\u00fchrer"},{"key":"3","first-page":"130","article-title":"Detecting the DGA-based malicious domain names","author":"Y. Zhang"},{"key":"4","first-page":"47","article-title":"DGASensor: fast detection for DGA-based malwares","author":"X. Luo"},{"issue":"2","key":"5","first-page":"143","article-title":"The impact of GDPR on WHOIS: implications for businesses facing cybercrime","volume":"2","author":"A. J. Ferrante","year":"2018","journal-title":"Cyber Security: A Peer-Reviewed Journal"},{"key":"6","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2017.11.018"},{"key":"7","first-page":"1","article-title":"Detecting DGA domains with recurrent neural networks and side information","author":"R. R. Curtin"},{"issue":"6","key":"8","doi-asserted-by":"crossref","first-page":"67","DOI":"10.11648\/j.ijiis.20170606.11","article-title":"Classification for DGA-based malicious domain names with deep learning architectures","volume":"6","author":"Z. Feng","year":"2017","journal-title":"Int\u2019l Journal of Intelligent Information Systems"},{"key":"9","first-page":"1","article-title":"Character level based detection of DGA domain names","author":"B. Yu"},{"key":"10","article-title":"Predicting domain generation algorithms with long short-term memory networks","author":"J. Woodbridge","year":"2016"},{"key":"11","doi-asserted-by":"publisher","DOI":"10.3390\/app9204205"},{"key":"12","first-page":"683","article-title":"Inline DGA detection with deep networks","author":"B. Yu"},{"key":"13","doi-asserted-by":"publisher","DOI":"10.1109\/78.650093"},{"key":"14","first-page":"1","article-title":"Ensemble methods in machine learning,","author":"T. G. Dietterich"},{"key":"15","first-page":"48","article-title":"Detecting algorithmically generated malicious domain names,","author":"S. Yadav"},{"key":"16","first-page":"408","article-title":"Detecting machine generated domain names based on morpheme features","author":"Z. Wei-wei"},{"key":"17","first-page":"192","article-title":"Phoenix: DGA-based botnet tracking and intelligence","author":"S. Schiavoni"},{"key":"18","first-page":"491","article-title":"From throw-away traffic to bots: detecting the rise of DGA-based malware","author":"M. Antonakakis"},{"key":"19","doi-asserted-by":"publisher","DOI":"10.1109\/tnet.2012.2184552"},{"key":"20"},{"key":"21","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2018.01.012"},{"key":"22","article-title":"Attention is all you need","volume":"34","author":"A. Vaswani","year":"2017","journal-title":"Advances in Neural Information Processing Systems"},{"key":"23","article-title":"expose: a character-level convolutional neural network with embeddings for detecting malicious urls","volume":"34","author":"J. Saxe","year":"2017","journal-title":"File Paths, and Registry Keys"},{"key":"24","doi-asserted-by":"publisher","DOI":"10.1613\/jair.614"},{"key":"25"},{"key":"26"},{"key":"27"},{"issue":"11","key":"28","doi-asserted-by":"crossref","first-page":"1","DOI":"10.3390\/fi11110237","article-title":"Feature fusion text classification model combining CNN and BiGRU with multi-attention mechanism","volume":"11","author":"J. Zhang","year":"2019","journal-title":"Future Internet"},{"key":"29","doi-asserted-by":"crossref","first-page":"127","DOI":"10.4018\/978-1-5225-8407-0.ch007","article-title":"Adversarial attacks and defenses in malware detection classifiers","volume":"34","author":"T. S. John","year":"2019","journal-title":"Handbook of Research on Cloud Computing and Big Data Applications In IoT, IGI Global"},{"key":"30","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019"},{"key":"31","article-title":"Maskdga: a black-box evasion technique against dga classifiers and adversarial defenses","author":"L. Sidi","year":"2019"},{"key":"32","article-title":"Domaingan: generating adversarial examples to attack domain generation algorithm classifiers","author":"I. Corley","year":"2020"}],"container-title":["Security and Communication Networks"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/downloads.hindawi.com\/journals\/scn\/2021\/8887881.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/downloads.hindawi.com\/journals\/scn\/2021\/8887881.xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/downloads.hindawi.com\/journals\/scn\/2021\/8887881.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,1,19]],"date-time":"2021-01-19T19:50:12Z","timestamp":1611085812000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.hindawi.com\/journals\/scn\/2021\/8887881\/"}},"subtitle":[],"editor":[{"given":"Savio","family":"Sciancalepore","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"editor"}]}],"short-title":[],"issued":{"date-parts":[[2021,1,18]]},"references-count":32,"alternative-id":["8887881","8887881"],"URL":"https:\/\/doi.org\/10.1155\/2021\/8887881","relation":{},"ISSN":["1939-0122","1939-0114"],"issn-type":[{"value":"1939-0122","type":"electronic"},{"value":"1939-0114","type":"print"}],"subject":[],"published":{"date-parts":[[2021,1,18]]}}}