1
Return

MDDB-AETB: Malicious Domain Detection Boosting Based on Alignment with Encrypted Traffic Behavior in Restricted Scenarios

delete2025-11-26
delete0
PRE
AI
M
Mengrui Cao
G
Gaopeng Gou
J
Junzheng Shi
G
Gang Xiong
Z
Zhen Li
J
Jiayu Li
DOI:10.1016/j.cose.2025.104785delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Malicious domain detection is a key challenge in network security. Traditional methods cannot achieve effective malicious domain detection in real-world limited scenarios with limited labeled data and insufficient domain relationships, which we focus on in this paper. Based on the insight that domains with similar encrypted traffic behavior are expected to share similar representations in the embedding space, we propose MDDB-AETB, boosting malicious domain detection based on alignment with encrypted traffic behavior. We extract text and behavior features from TLS messages of encrypted traffic. For behavior features, we measure the similarity of statistical features as self-supervised learning labels. With these labels, we fine-tune the pre-trained model whose input is domain text, getting an optimized embedding representation model. The loss function for fine-tuning combines mean square error (MSE) loss and contrastive loss to capture the subtle behavior of encrypted traffic, enhancing its detection capability. We evaluate MDDB-AETB against three state-of-the-art baselines, the results show that MDDB-AETB consistently achieves the best performance across all test set proportions, reaching up to 99% F1-score while maintaining stable advantages even under limited training data.

Journal

C
Computers and Security
IF:
5.4
Papers:
4.6K
Citations:
1.4W

Organization

I
Institute of Information Engineering
Scholars:
319
Papers: 109
Citations: 439
Cited Papers

Cited Papers

Citing Papers

Citing Papers