Using side channel TCP features for real-time detection of malware connections

被引:9
|
作者
Stergiopoulos, George [1 ]
Chronopoulou, Georgia [1 ]
Bitsikas, Evangelos [1 ]
Tsalis, Nikolaos [1 ]
Gritzalis, Dimitris [1 ]
机构
[1] Athens Univ Econ & Business, Dept Informat, Informat Secur & Crit Infrastruct Protect INFOSEC, Athens, Greece
关键词
Malware traffic; malware detection; machine learning; defacement; CART; botnet; reverse shells; trojan;
D O I
10.3233/JCS-191286
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
During the past years, deep packet inspection has been prevalent in network intrusion detection systems. Most solutions employ complex algorithms to analyze the intended behaviour and underlying characteristics of packets and their payloads, in an effort to detect and prevent malicious users and software from communicating over business intranets and wider networks. Still, there are multiple issues that inhibit their success rate. Most signature-based security software is plagued by false positives and/or false negatives. On the other hand, behavioral-based solutions achieve better detection rates but need to analyze large amounts of traffic. In this article, we present a real-time network traffic monitoring system that implements machine learning over side channel characteristics of TCP network packets to distinguish normal from malicious TCP sessions, even when encryption is in place. We test in university networks and test multiple different types of traffic. We show that, our approach (i) requires notably less information to achieve similar (if not better) detection rates, (ii) works over encrypted traffic as well, and (iii) has notably low false positives and false negatives in everyday case study scenarios.
引用
收藏
页码:507 / 520
页数:14
相关论文
共 50 条
  • [21] Learning Fast and Slow: Propedeutica for Real-Time Malware Detection
    Sun, Ruimin
    Yuan, Xiaoyong
    He, Pan
    Zhu, Qile
    Chen, Aokun
    Gregio, Andre
    Oliveira, Daniela
    Li, Xiaolin
    IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2022, 33 (06) : 2518 - 2529
  • [22] A Novel Side-Channel in Real-Time Schedulers
    Chen, Chien-Ying
    Mohan, Sibin
    Pellizzoni, Rodolfo
    Bobba, Rakesh B.
    Kiyavash, Negar
    25TH IEEE REAL-TIME AND EMBEDDED TECHNOLOGY AND APPLICATIONS SYMPOSIUM (RTAS 2019), 2019, : 90 - 102
  • [23] Real-time Detection of Cache Side-channel Attack Using Non-cache Hardware Events
    Kim, Hodong
    Hahn, Changhee
    Hur, Junbeom
    35TH INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING (ICOIN 2021), 2021, : 28 - 31
  • [24] Real-time obstacle detection with motion features using monocular vision
    Jia, Baozhi
    Liu, Rui
    Zhu, Ming
    VISUAL COMPUTER, 2015, 31 (03): : 281 - 293
  • [25] Real-Time Human Detection Using Relational Depth Similarity Features
    Ikemura, Sho
    Fujiyoshi, Hironobu
    COMPUTER VISION - ACCV 2010, PT IV, 2011, 6495 : 25 - 38
  • [26] Real-time face and head detection using four directional features
    Ishii, Y
    Hongo, H
    Yamamoto, K
    Niwa, Y
    SIXTH IEEE INTERNATIONAL CONFERENCE ON AUTOMATIC FACE AND GESTURE RECOGNITION, PROCEEDINGS, 2004, : 403 - 408
  • [27] Automatic real-time detection of endoscopic procedures using temporal features
    Stanek, Sean R.
    Tavanapong, Wallapak
    Wong, Johnny
    Oh, Jung Hwan
    de Groen, Piet C.
    COMPUTER METHODS AND PROGRAMS IN BIOMEDICINE, 2012, 108 (02) : 524 - 535
  • [28] Real-Time Traffic Sign Detection Using SURF Features on FPGA
    Zhao, Jin
    Zhu, Sichao
    Huang, Xinming
    2013 IEEE CONFERENCE ON HIGH PERFORMANCE EXTREME COMPUTING (HPEC), 2013,
  • [29] Real-time obstacle detection with motion features using monocular vision
    Baozhi Jia
    Rui Liu
    Ming Zhu
    The Visual Computer, 2015, 31 : 281 - 293
  • [30] Real-time Discrimination of Frontal Face Using Integral Channel Features and Adaboost
    Yang, Jian
    Xu, Wei
    Liu, Yu
    Zhang, Maojun
    2014 5TH IEEE INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING AND SERVICE SCIENCE (ICSESS), 2014, : 360 - 363