Robust Detection of Malicious URLs With Self-Paced Wide & Deep Learning

As cybercrimes grow in scale with devastating economic costs, it is important to protect potential victims against diverse attacks. In spite of the diversity of cybercrimes, it is the uniform resource locators (URLs) that connect vulnerable users with potential attacks. Although numerous solutions (e.g., rule-based solutions and machine learning-based methods) are proposed for malicious URL detection, they cannot provide robust performance due to the diversity of cybercrimes and cannot cope with the explosive growth of malicious URLs with the evolution of obfuscation strategies. In this paper, we propose a deep learning-based system, dubbed as <italic>CyberLen</italic>, to detect malicious URLs robustly and effectively. Specifically, we use factorization machine (FM) to learn the latent interaction among lexical features. For the deep structural features, position embedding is introduced for token vectorization to reduce the ambiguity of URL tokens. Meanwhile, temporal convolution network (TCN) is utilized to learn the long-distance dependency among URL tokens. To fuse heterogeneous features, self-paced wide <inline-formula><tex-math notation="LaTeX">$\&$</tex-math><alternatives><mml:math><mml:mo>&</mml:mo></mml:math><inline-graphic xlink:href="liang-ieq2-3121388.gif"/></alternatives></inline-formula> deep learning strategy is proposed to train a robust model effectively. The proposed solution is evaluated on a large-scale URL dataset. Our experimental results show that position embedding is constructive to reducing the ambiguity of URL tokens, and the self-paced wide <inline-formula><tex-math notation="LaTeX">$\&$</tex-math><alternatives><mml:math><mml:mo>&</mml:mo></mml:math><inline-graphic xlink:href="liang-ieq3-3121388.gif"/></alternatives></inline-formula> deep learning strategy shows superior performance in terms of F1 score and convergence speed.

Paper

Full text

PDF

Robust Detection of Malicious URLs With Self-Paced Wide & Deep Learning

Semantic Scholar · Computer Science · 2022

Abstract

As cybercrimes grow in scale with devastating economic costs, it is important to protect potential victims against diverse attacks. In spite of the diversity of cybercrimes, it is the uniform resource locators (URLs) that connect vulnerable users with potential attacks. Although numerous solutions (e.g., rule-based solutions and machine learning-based methods) are proposed for malicious URL detection, they cannot provide robust performance due to the diversity of cybercrimes and cannot cope with the explosive growth of malicious URLs with the evolution of obfuscation strategies. In this paper, we propose a deep learning-based system, dubbed as <italic>CyberLen</italic>, to detect malicious URLs robustly and effectively. Specifically, we use factorization machine (FM) to learn the latent interaction among lexical features. For the deep structural features, position embedding is introduced for token vectorization to reduce the ambiguity of URL tokens. Meanwhile, temporal convolution network (TCN) is utilized to learn the long-distance dependency among URL tokens. To fuse heterogeneous features, self-paced wide <inline-formula><tex-math notation="LaTeX">$&$</tex-math><alternatives>mml:mathmml:mo&</mml:mo></mml:math><inline-graphic xlink:href="liang-ieq2-3121388.gif"/></alternatives></inline-formula> deep learning strategy is proposed to train a robust model effectively. The proposed solution is evaluated on a large-scale URL dataset. Our experimental results show that position embedding is constructive to reducing the ambiguity of URL tokens, and the self-paced wide <inline-formula><tex-math notation="LaTeX">$&$</tex-math><alternatives>mml:mathmml:mo&</mml:mo></mml:math><inline-graphic xlink:href="liang-ieq3-3121388.gif"/></alternatives></inline-formula> deep learning strategy shows superior performance in terms of F1 score and convergence speed.

Similar papers

© 2026 NYSGPT2525 LLC