REdiREKT: Extracting Malicious Redirections from Exploit Kit Traffic

被引:0
|
作者
Burgess, Jonah [1 ]
Carlin, Domhnall [1 ]
O'Kane, Philip [1 ]
Sezer, Sakir [1 ]
机构
[1] Queens Univ, Ctr Secure Informat Technol, Belfast, Antrim, North Ireland
关键词
Exploit Kits; Web Security; Malware; WEBSITES;
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
This paper proposes REdiREKT, a system which utilises the open-source Zeek Intrusion Detection System (IDS) to map HTTP redirection chains observed in Exploit Kit (EK) attacks and extracts distinguishing features to assist machine learning (ML). We build a ground-truth dataset of EK samples, ensuring that the redirection chains for every sample are accurate and reusable in future experiments. By processing a unique combination of 9 redirection techniques, REdiREKT was able to correctly extract 96.52% of malicious domains from 1279 EK samples, spanning 28 families and 8 campaigns, and, only failed to extract 0.7% of malicious chains. Using the VirusTotal API to filter out domains flagged as malicious, we build a benign dataset from the Alexa top 10k websites, extracting 12,783 domains from 5910 redirection chains. The malicious redirection data is divided into yearly and family-based categories and compared to the benign results. Based on our analysis of the collected data, we extract and store 48 key features from websites within the redirection chains that could aid future ML-based detection efforts. Finally, we evaluate the performance of REdiREKT, compare it with existing research, and, suggest use-cases and future areas of work.
引用
收藏
页数:9
相关论文
共 46 条
  • [31] Extracting Traffic Primitives Directly From Naturalistically Logged Data for Self-Driving Applications
    Wang, Wenshuo
    Zhao, Ding
    [J]. IEEE ROBOTICS AND AUTOMATION LETTERS, 2018, 3 (02): : 1223 - 1229
  • [32] EXTRACTING HIGH-VOLUME TRAFFIC ROUTES FROM AIS SPATIAL DISTRIBUTION MAPS.
    Grobler, T. L.
    Kleynhans, W.
    [J]. 2019 IEEE INTERNATIONAL GEOSCIENCE AND REMOTE SENSING SYMPOSIUM (IGARSS 2019), 2019, : 10031 - 10034
  • [33] A Method for Extracting Traffic Parameters from Drone Videos to Assist Car-Following Modeling
    Zhang, Xiangzhou
    Shi, Zhongke
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2024, 15 (01) : 380 - 391
  • [34] Extracting Key Traffic Parameters from UAV Video with On-Board Vehicle Data Validation
    Shan, Donghui
    Lei, Tian
    Yin, Xiaohong
    Luo, Qin
    Gong, Lei
    [J]. SENSORS, 2021, 21 (16)
  • [35] Tips for extracting total RNA from chondrocytes cultured in agarose gel using a silica-based membrane kit
    Mio, K
    Kirkham, J
    Bonass, WA
    [J]. ANALYTICAL BIOCHEMISTRY, 2006, 351 (02) : 314 - 316
  • [36] Extracting information from the cutting force signal to explain and exploit its discrepancy between up and down slot milling at the same chip thickness
    Bouzakis, K. -d.
    Gokcen, M. -g.
    Bouzakis, E.
    Bouzakis, A.
    Ipekoglu, M.
    Osmanoglu, E.
    Batuk, A. -u.
    [J]. JOURNAL OF MATERIALS PROCESSING TECHNOLOGY, 2024, 331
  • [37] Extracting Traffic Information from Web Texts with a D-S Evidence Theory Based Approach
    Qiu, Peiyuan
    Lu, Feng
    Zhang, Hengcai
    [J]. 2013 21ST INTERNATIONAL CONFERENCE ON GEOINFORMATICS (GEOINFORMATICS), 2013,
  • [38] A novel relationship-oriented clustering approach for extracting relational patterns from the traffic tangled data
    Darabi, Somayeh Akhavan
    Baradaran, Vahid
    [J]. TRANSPORTATION LETTERS-THE INTERNATIONAL JOURNAL OF TRANSPORTATION RESEARCH, 2023, 15 (07): : 805 - 821
  • [39] AUTOMATICALLY EXTRACTING TRAFFIC DATA FROM VIDEOTAPE USING THE CLIP4 PARALLEL IMAGE-PROCESSOR
    HOOSE, N
    WILLUMSEN, LG
    [J]. PATTERN RECOGNITION LETTERS, 1987, 6 (03) : 199 - 213
  • [40] A Visual Analytics Approach for Extracting Spatio-Temporal Urban Mobility Information from Mobile Network Traffic
    Sagl, Guenther
    Loidl, Martin
    Beinat, Euro
    [J]. ISPRS INTERNATIONAL JOURNAL OF GEO-INFORMATION, 2012, 1 (03): : 256 - 271