Real Time Detection of Malware Activities by Analyzing Darknet Traffic Using Graphical Lasso

被引:7
|
作者
Han, Chansu [1 ,2 ]
Shimamura, Jumpei [3 ]
Takahashi, Takeshi [1 ]
Inoue, Daisuke [1 ]
Kawakita, Masanori [2 ,4 ]
Takeuchi, Jun'ichi [1 ,2 ]
Nakao, Koji [1 ]
机构
[1] Natl Inst Informat & Commun Technol, Koganei, Tokyo, Japan
[2] Kyushu Univ, Fukuoka, Japan
[3] Clwit Inc, Tokyo, Japan
[4] Nagoya Univ, Nagoya, Aichi, Japan
来源
2019 18TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS/13TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING (TRUSTCOM/BIGDATASE 2019) | 2019年
关键词
Real-time detection; Malware; Network scan; Darknet; Cooperation; Outlier detection;
D O I
10.1109/TrustCom/BigDataSE.2019.00028
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recent malware evolutions have rendered cyberspace less secure, and we are currently witnessing an increasing number of severe security incidents. To minimize the impact of malware activities, it is important to detect them promptly and precisely. We have been working on this issue by monitoring traffic coming into unused IP address spaces, i.e., the darknet. On our darknet, Internet-wide scans from malware are observed as if they are coordinated or working cooperatively. Based on this observation, our earlier method monitored network traffic arriving at our darknet, estimated the degree of cooperation between each pair of the source hosts, and detected significant changes in cooperation among source hosts as a sign of newly activated malware activities. However, this method does not work in real time, and thus, it is impractical. In this study, we extend our earlier work and propose an online processing algorithm, making it possible to detect malware activities in real time. In our evaluation, we measure the detection performance of the proposed method with our proof-of-concept implementation to demonstrate its feasibility and effectiveness in terms of detecting the rise of new malware activities in real time.
引用
收藏
页码:144 / 151
页数:8
相关论文
共 50 条
  • [31] Real-Time Vehicle Detection in Urban Traffic Using AdaBoost
    Park, Jong-Min
    Choi, Hyun-Chul
    Oh, Se-Young
    IEEE/RSJ 2010 INTERNATIONAL CONFERENCE ON INTELLIGENT ROBOTS AND SYSTEMS (IROS 2010), 2010, : 3598 - 3603
  • [32] Real-time detection of traffic events using smart cameras
    Macesic, M.
    Jelaca, V.
    Nino-Castaneda, J. O.
    Prodanovic, N.
    Panic, M.
    Pizurica, A.
    Crnojevic, V.
    Philips, W.
    INTELLIGENT ROBOTS AND COMPUTER VISION XXIX: ALGORITHMS AND TECHNIQUES, 2012, 8301
  • [33] Real-Time Traffic Sign Detection using Capsule Network
    Pari, Neelavathy S.
    Mohana, T.
    Akshaya, V
    2019 11TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING (ICOAC 2019), 2019, : 193 - 196
  • [34] Real-Time Traffic Light Detection Using Color Density
    Tai Huu-Phuong
    Cuong Cao Pham
    Tien Phuoc Nguyen
    Tin Trung Duong
    Jeon, Jae Wook
    2016 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS-ASIA (ICCE-ASIA), 2016,
  • [35] Real-time Traffic Incident Detection Using an Autoencoder Model
    Yang, Huan
    Wang, Yu
    Zhao, Han
    Zhu, Jinlin
    Wang, Danwei
    2020 IEEE 23RD INTERNATIONAL CONFERENCE ON INTELLIGENT TRANSPORTATION SYSTEMS (ITSC), 2020,
  • [36] Real Time Road Traffic Event Detection Using Twitter and Spark
    Pandhare, Ketan R.
    Shah, Medha A.
    PROCEEDINGS OF THE 2017 INTERNATIONAL CONFERENCE ON INVENTIVE COMMUNICATION AND COMPUTATIONAL TECHNOLOGIES (ICICCT), 2017, : 445 - 449
  • [37] Using Object Detection Network for Malware Detection and Identification in Network Traffic Packets
    Du, Chunlai
    Liu, Shenghui
    Si, Lei
    Guo, Yanhui
    Jin, Tong
    CMC-COMPUTERS MATERIALS & CONTINUA, 2020, 64 (03): : 1785 - 1796
  • [38] Analyzing spatial mobility patterns with time-varying graphical lasso: Application to COVID-19 spread
    Degano, Ivan L.
    Lotito, Pablo A.
    TRANSACTIONS IN GIS, 2021, 25 (05) : 2660 - 2674
  • [39] A Near Real-Time Scheme for Collecting and Analyzing IoT Malware Artifacts at Scale
    Khoury, Joseph
    Pour, Morteza Safaei
    Bou-Harb, Elias
    PROCEEDINGS OF THE 17TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, ARES 2022, 2022,
  • [40] Automated Detection of Malware Activities Using Nonnegative Matrix Factorization
    Han, Chansu
    Takeuchi, Jun'ichi
    Takahashi, Takeshi
    Inoue, Daisuke
    2021 IEEE 20TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2021), 2021, : 548 - 556