Alert correlation framework for malware detection by anomaly-based packet payload analysis

被引:17
|
作者
Maestre Vidal, Jorge [1 ]
Sandoval Orozco, Ana Luella [1 ]
Garcia Villalba, Luis Javier [1 ]
机构
[1] Univ Complutense Madrid, Sch Comp Sci, Dept Software Engn & Artificial Intelligence DISI, Grp Anal Secur & Syst, Off 431,Calle Prof Jose Garcia Santesmases S-N, E-28040 Madrid, Spain
关键词
Alert correlation; Anomalies; Intrusion detection system; Malware; Network; Payload; INTRUSION DETECTION; ATTACK SCENARIOS; MODEL; MULTISTEP; ALGORITHM; NETWORKS; SYSTEMS;
D O I
10.1016/j.jnca.2017.08.010
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Intrusion detection based on identifying anomalies typically emits a large amount of reports about the malicious activities monitored; hence information gathered is difficult to manage. In this paper, an alert correlation system capable of dealing with this problem is introduced. The work carried out has focused on the study of a particular family of sensors, namely those which analyze the payload of network traffic looking for malware. Unlike conventional approaches, the information provided by the network packet headers is not taken into account. Instead, the proposed strategy considers the payload of the monitored traffic and the characteristics of the models built during the training of such detectors, in this way supporting the general-purpose incident management tools. It aims to analyze, classify and prioritize alerts issued, based on two criteria: the risk of threats being genuine and their nature. Incidences are studied both in a one-to-one and in a group context. This implies the consideration of two different processing layers: The first one allows fast reactions and resilience against certain adversarial attacks, and on the other hand, the deeper layer facilitates the reconstruction of attack scenarios and provides an overview of potential threats. Experiments conducted by analyzing real traffic demonstrated the effectiveness of the proposal.
引用
收藏
页码:11 / 22
页数:12
相关论文
共 50 条
  • [1] Quantitative Criteria for Alert Correlation of Anomaly-based NIDS
    Vidal, J. M.
    Orozco, A. L. S.
    Villalba, L. J. G.
    IEEE LATIN AMERICA TRANSACTIONS, 2015, 13 (10) : 3461 - 3466
  • [2] Deep anomaly detection in packet payload
    Liu, Jiaxin
    Song, Xucheng
    Zhou, Yingjie
    Peng, Xi
    Zhang, Yanru
    Liu, Pei
    Wu, Dapeng
    Zhu, Ce
    NEUROCOMPUTING, 2022, 485 : 205 - 218
  • [3] Anomaly-Based NIDS: A Review of Machine Learning Methods on Malware Detection
    Raffie, Mohd Z. A.
    Zuhairi, Megat F.
    Akimi, Shadil Z. A.
    Dao, Hassan
    2016 PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY (ICICTM), 2016, : 266 - 270
  • [4] Application of anomaly detection in alert correlation analysis
    Wang, Juan
    Qin, Zhi-Guang
    Ye, Li
    Jin, Jing
    Jiefangjun Ligong Daxue Xuebao/Journal of PLA University of Science and Technology (Natural Science Edition), 2009, 10 (03): : 278 - 280
  • [5] A Transformer-Based Framework for Payload Malware Detection and Classification
    Stein, Kyle
    Mahyari, Arash
    Francia, Guillermo, III
    El-Sheikh, Eman
    2024 IEEE 5TH ANNUAL WORLD AI IOT CONGRESS, AIIOT 2024, 2024, : 0105 - 0111
  • [6] AMD-EC: Anomaly-based Android Malware Detection using Ensemble Classifiers
    Ghaffari, Fariba
    Abadi, Mahdi
    Tajoddin, Asghar
    2017 25TH IRANIAN CONFERENCE ON ELECTRICAL ENGINEERING (ICEE), 2017, : 2247 - 2252
  • [7] A white-box anomaly-based framework for database leakage detection
    Costante, E.
    den Hartog, J.
    Petkovic, Milan
    Etalle, S.
    Pechenizkiy, M.
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2017, 32 : 27 - 46
  • [8] Collaborative anomaly-based attack detection
    Gamer, Thomas
    Scharf, Michael
    Schoeller, Marcus
    SELF-ORGANIZING SYSTEMS, PROCEEDINGS, 2007, 4725 : 280 - +
  • [9] An algorithm for anomaly-based botnet detection
    Binkley, James R.
    Singh, Suresh
    USENIX ASSOCIATION PROCEEDINGS OF THE 2ND WORKSHOP ON STEPS TO REDUCING UNWANTED TRAFFIC ON THE INTERNET, 2006, : 43 - +
  • [10] Benchmarking anomaly-based detection systems
    Maxion, RA
    Tan, KMC
    DSN 2000: INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS, PROCEEDINGS, 2000, : 623 - 630