Detecting and Exploring Malicious Websites through Multi-Message Passing Heterogeneous Neural Network

Xiaoyu Fang, Xiaoqing Ma, Cong Wang, Yan Niu, Ma Li Ya, Tianmu Gao, Rong Yang · 2024

Identifying and blocking malicious domains is one of the most direct and effective ways to combat malicious websites. In recent years, tools and technologies such as domain registration services, code repositories, and Domain-Flux have been exploited to generate malicious websites, enabling them to quickly "reincarnate" after being identified and shut down. Detecting methods for such malicious website domains are gradually shifting from the Belief Propagation (BP) algorithm to the Graph Neural Network (GNN) algorithm because the latter excels at aggregating neighboring node information to integrate node representations and graph embeddings. However, cloud services, Content Delivery Network (CDN), and Carrier-Grade Network Address Translation (CGNAT) often lead to benign-malicious co-location for domains, causing miscommunication in messages passing based on domain association relationships, thus reducing detection accuracy. To overcome this limitation, this paper proposes a malicious website domain detection algorithm based on one Multi-Message Passing Heterogeneous Neural Network (HMPN) framework. We apply this method to real-world network traffic scenarios and find that it achieves a Macro-Average F1 score of 91.70%, outperforming the baselines. We further conduct a measurement and analysis of the malicious websites’ industrial characteristics to better explore and detect malicious websites.

Read the paper · More papers on PaperTik