Real Time Detection of Malware Activities by Analyzing Darknet Traffic Using Graphical Lasso

被引:7
|
作者
Han, Chansu [1 ,2 ]
Shimamura, Jumpei [3 ]
Takahashi, Takeshi [1 ]
Inoue, Daisuke [1 ]
Kawakita, Masanori [2 ,4 ]
Takeuchi, Jun'ichi [1 ,2 ]
Nakao, Koji [1 ]
机构
[1] Natl Inst Informat & Commun Technol, Koganei, Tokyo, Japan
[2] Kyushu Univ, Fukuoka, Japan
[3] Clwit Inc, Tokyo, Japan
[4] Nagoya Univ, Nagoya, Aichi, Japan
关键词
Real-time detection; Malware; Network scan; Darknet; Cooperation; Outlier detection;
D O I
10.1109/TrustCom/BigDataSE.2019.00028
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recent malware evolutions have rendered cyberspace less secure, and we are currently witnessing an increasing number of severe security incidents. To minimize the impact of malware activities, it is important to detect them promptly and precisely. We have been working on this issue by monitoring traffic coming into unused IP address spaces, i.e., the darknet. On our darknet, Internet-wide scans from malware are observed as if they are coordinated or working cooperatively. Based on this observation, our earlier method monitored network traffic arriving at our darknet, estimated the degree of cooperation between each pair of the source hosts, and detected significant changes in cooperation among source hosts as a sign of newly activated malware activities. However, this method does not work in real time, and thus, it is impractical. In this study, we extend our earlier work and propose an online processing algorithm, making it possible to detect malware activities in real time. In our evaluation, we measure the detection performance of the proposed method with our proof-of-concept implementation to demonstrate its feasibility and effectiveness in terms of detecting the rise of new malware activities in real time.
引用
收藏
页码:144 / 151
页数:8
相关论文
共 50 条
  • [1] Real-Time Detection of Global Cyberthreat Based on Darknet by Estimating Anomalous Synchronization Using Graphical Lasso
    Han, Chansu
    Shimamura, Jumpei
    Takahashi, Takeshi
    Inoue, Daisuke
    Takeuchi, Jun'ichi
    Nakao, Koji
    IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2020, E103D (10) : 2113 - 2124
  • [2] Real time malware detection in encrypted network traffic using machine learning with time based features
    Singh, Abhay Pratap
    Singh, Mahendra
    JOURNAL OF DISCRETE MATHEMATICAL SCIENCES & CRYPTOGRAPHY, 2023, 26 (03): : 841 - 850
  • [3] A Time Series Approach for Inferring Orchestrated Probing Campaigns by Analyzing Darknet Traffic
    Bou-Harb, Elias
    Debbabi, Mourad
    Assi, Chadi
    PROCEEDINGS 10TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY ARES 2015, 2015, : 180 - 185
  • [4] Detection and Classification of Moving Objects by Using Real Time Traffic Flux Through Differential and Graphical analysis
    Mohana, H. S.
    Ashwathakumar, M.
    Shivakumar, G.
    Manjunatha, K. C.
    2009 1ST INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE, COMMUNICATION SYSTEMS AND NETWORKS(CICSYN 2009), 2009, : 414 - +
  • [5] Botnet Detection Using Graphical Lasso with Graph Density
    Han, Chansu
    Kono, Kento
    Tanaka, Shoma
    Kawakita, Masanori
    Takeuchi, Jun'ichi
    NEURAL INFORMATION PROCESSING, ICONIP 2016, PT I, 2016, 9947 : 537 - 545
  • [6] A study of IoT malware activities using association rule learning for darknet sensor data
    Ozawa, Seiichi
    Ban, Tao
    Hashimoto, Naoki
    Nakazato, Junji
    Shimamura, Jumpei
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2020, 19 (01) : 83 - 92
  • [7] A study of IoT malware activities using association rule learning for darknet sensor data
    Seiichi Ozawa
    Tao Ban
    Naoki Hashimoto
    Junji Nakazato
    Jumpei Shimamura
    International Journal of Information Security, 2020, 19 : 83 - 92
  • [8] Detection and classification of darknet traffic using machine learning methods
    Ugurlu, Mesut
    Dogru, Ibrahim Alper
    Arslan, Recep Sinan
    JOURNAL OF THE FACULTY OF ENGINEERING AND ARCHITECTURE OF GAZI UNIVERSITY, 2023, 38 (03): : 1737 - 1746
  • [9] Network-wide traffic state estimation using a mixture Gaussian graphical model and graphical lasso
    Hara, Yusuke
    Suzuki, Junpei
    Kuwahara, Masao
    Transportation Research Part C: Emerging Technologies, 2018, 86 : 622 - 638
  • [10] Estimating Travel Time Distributions Using Copula Graphical Lasso
    Prokhorchuk, Anatolii
    Payyada, Vishnu Prasad
    Dauwels, Justin
    Jaillet, Patrick
    2017 IEEE 20TH INTERNATIONAL CONFERENCE ON INTELLIGENT TRANSPORTATION SYSTEMS (ITSC), 2017,