REdiREKT: Extracting Malicious Redirections from Exploit Kit Traffic

被引:0
|
作者
Burgess, Jonah [1 ]
Carlin, Domhnall [1 ]
O'Kane, Philip [1 ]
Sezer, Sakir [1 ]
机构
[1] Queens Univ, Ctr Secure Informat Technol, Belfast, Antrim, North Ireland
关键词
Exploit Kits; Web Security; Malware; WEBSITES;
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
This paper proposes REdiREKT, a system which utilises the open-source Zeek Intrusion Detection System (IDS) to map HTTP redirection chains observed in Exploit Kit (EK) attacks and extracts distinguishing features to assist machine learning (ML). We build a ground-truth dataset of EK samples, ensuring that the redirection chains for every sample are accurate and reusable in future experiments. By processing a unique combination of 9 redirection techniques, REdiREKT was able to correctly extract 96.52% of malicious domains from 1279 EK samples, spanning 28 families and 8 campaigns, and, only failed to extract 0.7% of malicious chains. Using the VirusTotal API to filter out domains flagged as malicious, we build a benign dataset from the Alexa top 10k websites, extracting 12,783 domains from 5910 redirection chains. The malicious redirection data is divided into yearly and family-based categories and compared to the benign results. Based on our analysis of the collected data, we extract and store 48 key features from websites within the redirection chains that could aid future ML-based detection efforts. Finally, we evaluate the performance of REdiREKT, compare it with existing research, and, suggest use-cases and future areas of work.
引用
收藏
页数:9
相关论文
共 46 条
  • [21] Extracting Suspicious IP Addresses from WhatsApp Network Traffic in Cybercrime Investigations
    Kao, Da-Yu
    Chang, En-Cih
    Tsai, Fu-Ching
    [J]. 2019 21ST INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY (ICACT): ICT FOR 4TH INDUSTRIAL REVOLUTION, 2019, : 1108 - 1115
  • [22] TRAFFIC LIGHTS - EXTRACTING ORDER FROM THE CHAOS OF LONG-TERM-CARE
    TOMENSON, B
    BENBOW, SM
    JOLLEY, DJ
    [J]. INTERNATIONAL JOURNAL OF GERIATRIC PSYCHIATRY, 1994, 9 (12) : 985 - 987
  • [23] Extracting and Visualizing Relevant Data From Internet Traffic to Enhance Cyber Security
    Escrig, Teresa
    Hanna, Jordan
    Kwon, Shane
    Sorensen, Andrew
    McLane, Don
    Chung, Sam
    [J]. PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON CLOUD SECURITY MANAGEMENT (ICCSM-2013), 2013, : 18 - 26
  • [24] Extracting Decision Tree From Trained Deep Reinforcement Learning in Traffic Signal Control
    Zhu, Yuanyang
    Yin, Xiao
    Chen, Chunlin
    [J]. IEEE TRANSACTIONS ON COMPUTATIONAL SOCIAL SYSTEMS, 2023, 10 (04) : 1997 - 2007
  • [25] A machine learning pipeline for extracting decision-support features from traffic scenes
    Fraga, Vitor A.
    Schreiber, Lincoln V.
    da Silva, Marco Antonio C.
    Kunst, Rafael
    Barbosa, Jorge L. V.
    Ramos, Gabriel de O.
    [J]. AI COMMUNICATIONS, 2024, 37 (02) : 189 - 201
  • [26] Extracting Decision Tree from Trained Deep Reinforcement Learning in Traffic Signal Control
    Zhu, Yuanyang
    Yin, Xiao
    Li, Ruyu
    Chen, Chunlin
    [J]. 2021 INTERNATIONAL CONFERENCE ON CYBER-PHYSICAL SOCIAL INTELLIGENCE (ICCSI), 2021,
  • [27] Identifying Malicious DNS Tunnel Tools from DoH Traffic Using Hierarchical Machine Learning Classification
    Mitsuhashi, Rikima
    Satoh, Akihiro
    Jin, Yong
    Iida, Katsuyoshi
    Shinagawa, Takahiro
    Takai, Yoshiaki
    [J]. INFORMATION SECURITY (ISC 2021), 2021, 13118 : 238 - 256
  • [28] Kit-based, low-toxicity method for extracting and purifying fungal DNA from ectomycorrhizal roots
    Koide, RT
    Dickie, IA
    [J]. BIOTECHNIQUES, 2002, 32 (01) : 52 - +
  • [29] Comparison of a modified phenol/chloroform and commercial-kit methods for extracting DNA from horse fecal material
    Janabi, Ali H. D.
    Kerkhof, Lee J.
    McGuinness, Lora R.
    Biddle, Amy S.
    McKeever, Kenneth H.
    [J]. JOURNAL OF MICROBIOLOGICAL METHODS, 2016, 129 : 14 - 19
  • [30] Extracting dynamic spatial data from airborne imaging sensors to support traffic flow estimation
    Toth, C. K.
    Grejner-Brzezinska, D.
    [J]. ISPRS JOURNAL OF PHOTOGRAMMETRY AND REMOTE SENSING, 2006, 61 (3-4) : 137 - 148