{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/expose-a-character-level-convolutional-neural","title":"eXpose: A Character-Level Convolutional Neural Network with Embeddings For Detecting Malicious URLs, File Paths and Registry Keys","arxiv_id":"1702.08568","date":"2017-02-27","proceeding":null,"authors":["Joshua Saxe","Konstantin Berlin"],"abstract":"For years security machine learning research has promised to obviate the need\nfor signature based detection by automatically learning to detect indicators of\nattack. Unfortunately, this vision hasn't come to fruition: in fact, developing\nand maintaining today's security machine learning systems can require\nengineering resources that are comparable to that of signature-based detection\nsystems, due in part to the need to develop and continuously tune the\n\"features\" these machine learning systems look at as attacks evolve. Deep\nlearning, a subfield of machine learning, promises to change this by operating\non raw input signals and automating the process of feature design and\nextraction. In this paper we propose the eXpose neural network, which uses a\ndeep learning approach we have developed to take generic, raw short character\nstrings as input (a common case for security inputs, which include artifacts\nlike potentially malicious URLs, file paths, named pipes, named mutexes, and\nregistry keys), and learns to simultaneously extract features and classify\nusing character-level embeddings and convolutional neural network. In addition\nto completely automating the feature design and extraction process, eXpose\noutperforms manual feature extraction based baselines on all of the intrusion\ndetection problems we tested it on, yielding a 5%-10% detection rate gain at\n0.1% false positive rate compared to these baselines.","url_abs":"http://arxiv.org/abs/1702.08568v1","url_pdf":"http://arxiv.org/pdf/1702.08568v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"expose-a-character-level-convolutional-neural","repo_url":"https://github.com/MJafarMashhadi/Haplophysh","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"tf","reach":{"status":"unanswered"}},{"paper_slug":"expose-a-character-level-convolutional-neural","repo_url":"https://github.com/Mind23-2/MindCode-111","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":0,"framework":"mindspore","reach":null}],"tasks":[{"task_slug":"machine-learning","task_name":"BIG-bench Machine Learning"},{"task_slug":"intrusion-detection","task_name":"Intrusion Detection"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":null,"mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}