Using side channel TCP features for real-time detection of malware connections

被引:9
|
作者
Stergiopoulos, George [1 ]
Chronopoulou, Georgia [1 ]
Bitsikas, Evangelos [1 ]
Tsalis, Nikolaos [1 ]
Gritzalis, Dimitris [1 ]
机构
[1] Athens Univ Econ & Business, Dept Informat, Informat Secur & Crit Infrastruct Protect INFOSEC, Athens, Greece
关键词
Malware traffic; malware detection; machine learning; defacement; CART; botnet; reverse shells; trojan;
D O I
10.3233/JCS-191286
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
During the past years, deep packet inspection has been prevalent in network intrusion detection systems. Most solutions employ complex algorithms to analyze the intended behaviour and underlying characteristics of packets and their payloads, in an effort to detect and prevent malicious users and software from communicating over business intranets and wider networks. Still, there are multiple issues that inhibit their success rate. Most signature-based security software is plagued by false positives and/or false negatives. On the other hand, behavioral-based solutions achieve better detection rates but need to analyze large amounts of traffic. In this article, we present a real-time network traffic monitoring system that implements machine learning over side channel characteristics of TCP network packets to distinguish normal from malicious TCP sessions, even when encryption is in place. We test in university networks and test multiple different types of traffic. We show that, our approach (i) requires notably less information to achieve similar (if not better) detection rates, (ii) works over encrypted traffic as well, and (iii) has notably low false positives and false negatives in everyday case study scenarios.
引用
收藏
页码:507 / 520
页数:14
相关论文
共 50 条
  • [31] Assessing Real-time Malware Threats
    Gander, Matthias
    Sauerwein, Clemens
    Breu, Ruth
    2015 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE QUALITY, RELIABILITY AND SECURITY - COMPANION (QRS-C 2015), 2015, : 6 - 13
  • [32] A New Design of Smart Plug for Real-time IoT Malware Detection
    Li, Zhuoran
    Perez, Bryan
    Khan, Sabbir Ahmed
    Feldhaus, Brandon
    Zhao, Dan
    2021 IEEE MICROELECTRONICS DESIGN & TEST SYMPOSIUM (MDTS), 2021,
  • [33] Application of Deep Learning Models for Real-Time Automatic Malware Detection
    Gutierrez, Rommel
    Villegas-Ch, William
    Naranjo Godoy, Lorena
    Mera-Navarrete, Aracely
    Lujan-Mora, Sergio
    IEEE ACCESS, 2024, 12 : 107742 - 107756
  • [34] Identification and Evaluation of Discriminative Lexical Features of Malware URL for Real-Time Classification
    Olalere, Morufu
    Abdullah, Mohd Taufik
    Mahmod, Ramlan
    Abdullah, Azizol
    PROCEEDINGS OF 6TH INTERNATIONAL CONFERENCE ON COMPUTER AND COMMUNICATION ENGINEERING (ICCCE 2016), 2016, : 90 - 95
  • [35] Real-time Identification of Rogue WiFi Connections Using Environment-Independent Physical Features
    Liu, Pengfei
    Yang, Panlong
    Song, Wen-Zhan
    Yan, Yubo
    Li, Xiang-Yang
    IEEE CONFERENCE ON COMPUTER COMMUNICATIONS (IEEE INFOCOM 2019), 2019, : 190 - 198
  • [36] Dynamic Channel Allocation for Real-Time Connections in Highway Macrocellular Networks
    Mostafa A. Bassiouni
    Chun-Chin Fang
    Wireless Personal Communications, 2001, 19 : 121 - 138
  • [37] Dynamic channel allocation for real-time connections in highway macrocellular networks
    Bassiouni, MA
    Fang, CC
    WIRELESS PERSONAL COMMUNICATIONS, 2001, 19 (02) : 121 - 138
  • [38] MORE REAL-TIME CONNECTIONS
    TRACY, M
    DR DOBBS JOURNAL, 1988, 13 (08): : 114 - &
  • [39] Providing QoS to TCP and Real Time Connections in the Internet
    V. Venugopal Reddy
    Vinod Sharma
    M.B. Suma
    Queueing Systems, 2004, 46 : 461 - 480
  • [40] Providing QoS to TCP and real time connections in the Internet
    Reddy, VV
    Sharma, V
    Suma, MB
    QUEUEING SYSTEMS, 2004, 46 (3-4) : 461 - 480