Using Features of Encrypted Network Traffic to Detect Malware

被引:0
|
作者
Afzal, Zeeshan [1 ,2 ]
Brunstrom, Anna [2 ]
Lindskog, Stefan [2 ,3 ]
机构
[1] KTH Royal Inst Technol, Stockholm, Sweden
[2] Karlstad Univ, Karlstad, Sweden
[3] SINTEF Digital, Trondheim, Norway
来源
关键词
D O I
10.1007/978-3-030-70852-8_3
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Encryption on the Internet is as pervasive as ever. This has protected communications and enhanced the privacy of users. Unfortunately, at the same time malware is also increasingly using encryption to hide its operation. The detection of such encrypted malware is crucial, but the traditional detection solutions assume access to payload data. To overcome this limitation, such solutions employ traffic decryption strategies that have severe drawbacks. This paper studies the usage of encryption for malicious and benign purposes using large datasets and proposes a machine learning based solution to detect malware using connection and TLS metadata without any decryption. The classification is shown to be highly accurate with high precision and recall rates by using a small number of features. Furthermore, we consider the deployment aspects of the solution and discuss different strategies to reduce the false positive rate.
引用
收藏
页码:37 / 53
页数:17
相关论文
共 50 条
  • [1] Real time malware detection in encrypted network traffic using machine learning with time based features
    Singh, Abhay Pratap
    Singh, Mahendra
    [J]. JOURNAL OF DISCRETE MATHEMATICAL SCIENCES & CRYPTOGRAPHY, 2023, 26 (03): : 841 - 850
  • [2] Malware Detection by Analysing Encrypted Network Traffic with Neural Networks
    Prasse, Paul
    Machlica, Lukas
    Pevny, Tomas
    Havelka, Jiri
    Scheffer, Tobias
    [J]. MACHINE LEARNING AND KNOWLEDGE DISCOVERY IN DATABASES, ECML PKDD 2017, PT II, 2017, 10535 : 73 - 88
  • [3] A mobile malware detection method using behavior features in network traffic
    Wang, Shanshan
    Chen, Zhenxiang
    Yan, Qiben
    Yang, Bo
    Peng, Lizhi
    Jia, Zhongtian
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2019, 133 : 15 - 25
  • [4] Encrypted Malware Traffic Detection via Graph-based Network Analysis
    Fu, Zhuoqun
    Liu, Mingxuan
    Qin, Yue
    Zhang, Jia
    Zou, Yuan
    Yin, Qilei
    Li, Qi
    Duan, Haixin
    [J]. PROCEEDINGS OF 25TH INTERNATIONAL SYMPOSIUM ON RESEARCH IN ATTACKS, INTRUSIONS AND DEFENSES, RAID 2022, 2022, : 495 - 509
  • [5] Encrypted Traffic Classification Using Statistical Features
    Mahdavi, Ehsan
    Fanian, Ali
    Hassannejad, Homa
    [J]. ISECURE-ISC INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2018, 10 (01): : 29 - 43
  • [6] Poster Abstract: Encrypted Malware Traffic Detection Using Incremental Learning
    Lee, Insup
    Roh, Heejun
    Lee, Wonjun
    [J]. IEEE INFOCOM 2020 - IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (INFOCOM WKSHPS), 2020, : 1348 - 1349
  • [7] MEMTD: Encrypted Malware Traffic Detection Using Multimodal Deep Learning
    Zhang, Xiaotian
    Lu, Jintian
    Sun, Jiakun
    Xiao, Ruizhi
    Jin, Shuyuan
    [J]. WEB ENGINEERING (ICWE 2022), 2022, 13362 : 357 - 372
  • [8] MalDetect: A Structure of Encrypted Malware Traffic Detection
    Liu, Jiyuan
    Zeng, Yingzhi
    Shi, Jiangyong
    Yang, Yuexiang
    Wang, Rui
    He, Liangzhong
    [J]. CMC-COMPUTERS MATERIALS & CONTINUA, 2019, 60 (02): : 721 - 739
  • [9] Features to Detect Android Malware
    Urcuqui Lopez, Christian Camilo
    Delgado Villarreal, Jhoan Steven
    Perez Belalcazar, Andres Felipe
    Navarro Cadavid, Andres
    Diaz Cely, Javier Gustavo
    [J]. 2018 IEEE COLOMBIAN CONFERENCE ON COMMUNICATIONS AND COMPUTING (COLCOM), 2018,
  • [10] Minimizing Network Traffic Features for Android Mobile Malware Detection
    Arora, Anshul
    Peddoju, Sateesh K.
    [J]. 18TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING AND NETWORKING (ICDCN 2017), 2017,