Using side channel TCP features for real-time detection of malware connections

被引:9
|
作者
Stergiopoulos, George [1 ]
Chronopoulou, Georgia [1 ]
Bitsikas, Evangelos [1 ]
Tsalis, Nikolaos [1 ]
Gritzalis, Dimitris [1 ]
机构
[1] Athens Univ Econ & Business, Dept Informat, Informat Secur & Crit Infrastruct Protect INFOSEC, Athens, Greece
关键词
Malware traffic; malware detection; machine learning; defacement; CART; botnet; reverse shells; trojan;
D O I
10.3233/JCS-191286
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
During the past years, deep packet inspection has been prevalent in network intrusion detection systems. Most solutions employ complex algorithms to analyze the intended behaviour and underlying characteristics of packets and their payloads, in an effort to detect and prevent malicious users and software from communicating over business intranets and wider networks. Still, there are multiple issues that inhibit their success rate. Most signature-based security software is plagued by false positives and/or false negatives. On the other hand, behavioral-based solutions achieve better detection rates but need to analyze large amounts of traffic. In this article, we present a real-time network traffic monitoring system that implements machine learning over side channel characteristics of TCP network packets to distinguish normal from malicious TCP sessions, even when encryption is in place. We test in university networks and test multiple different types of traffic. We show that, our approach (i) requires notably less information to achieve similar (if not better) detection rates, (ii) works over encrypted traffic as well, and (iii) has notably low false positives and false negatives in everyday case study scenarios.
引用
收藏
页码:507 / 520
页数:14
相关论文
共 50 条
  • [1] Real-Time Detection for Cache Side Channel Attack using Performance Counter Monitor
    Cho, Jonghyeon
    Kim, Taehun
    Kim, Soojin
    Im, Miok
    Kim, Taehyun
    Shin, Youngjoo
    APPLIED SCIENCES-BASEL, 2020, 10 (03):
  • [2] Real-Time Detection on Cache Side Channel Attacks using Performance Counter Monitor
    Cho, JongHyeon
    Kim, TaeHyun
    Kim, TaeHun
    Shin, Youngjoo
    2019 10TH INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY CONVERGENCE (ICTC): ICT CONVERGENCE LEADING THE AUTONOMOUS FUTURE, 2019, : 175 - 177
  • [3] Real-Time Framework for Malware Detection Using Machine Learning Technique
    Mukesh, Sharma Divya
    Raval, Jigar A.
    Upadhyay, Hardik
    INFORMATION AND COMMUNICATION TECHNOLOGY FOR INTELLIGENT SYSTEMS (ICTIS 2017) - VOL 1, 2018, 83 : 173 - 182
  • [4] Automatic Detection of Various Malicious Traffic Using Side Channel Features on TCP Packets
    Stergiopoulos, George
    Talavari, Alexander
    Bitsikas, Evangelos
    Gritzalis, Dimitris
    COMPUTER SECURITY (ESORICS 2018), PT I, 2018, 11098 : 346 - 362
  • [5] A Chi-Square-Based Decision for Real-Time Malware Detection Using PE-File Features
    Belaoued, Mohamed
    Mazouzi, Smaine
    JOURNAL OF INFORMATION PROCESSING SYSTEMS, 2016, 12 (04): : 644 - 660
  • [6] A framework for metamorphic malware analysis and real-time detection
    Alam, Shahid
    Horspool, R. Nigel
    Traore, Issa
    Sogukpinar, Ibrahim
    COMPUTERS & SECURITY, 2015, 48 : 212 - 233
  • [7] Real-Time Human Detection Based on Optimized Integrated Channel Features
    Shen, Jifeng
    Zuo, Xin
    Yang, Wankou
    Liu, Guohai
    PATTERN RECOGNITION (CCPR 2014), PT II, 2014, 484 : 286 - 295
  • [8] Efficient and Interpretable Real-Time Malware Detection Using Random-Forest
    Mills, Alan
    Spyridopoulos, Theodoros
    Legg, Phil
    2019 INTERNATIONAL CONFERENCE ON CYBER SITUATIONAL AWARENESS, DATA ANALYTICS AND ASSESSMENT (CYBER SA), 2019,
  • [9] CloudRadar: A Real-Time Side-Channel Attack Detection System in Clouds
    Zhang, Tianwei
    Zhang, Yinqian
    Lee, Ruby B.
    RESEARCH IN ATTACKS, INTRUSIONS, AND DEFENSES, RAID 2016, 2016, 9854 : 118 - 140
  • [10] SCARF: Detecting Side-Channel Attacks at Real-time using Low-level Hardware Features
    Wang, Han
    Sayadi, Hossein
    Rafatirad, Setareh
    Sasan, Avesta
    Homayoun, Houman
    2020 26TH IEEE INTERNATIONAL SYMPOSIUM ON ON-LINE TESTING AND ROBUST SYSTEM DESIGN (IOLTS 2020), 2020,