Using side channel TCP features for real-time detection of malware connections

被引:9
|
作者
Stergiopoulos, George [1 ]
Chronopoulou, Georgia [1 ]
Bitsikas, Evangelos [1 ]
Tsalis, Nikolaos [1 ]
Gritzalis, Dimitris [1 ]
机构
[1] Athens Univ Econ & Business, Dept Informat, Informat Secur & Crit Infrastruct Protect INFOSEC, Athens, Greece
关键词
Malware traffic; malware detection; machine learning; defacement; CART; botnet; reverse shells; trojan;
D O I
10.3233/JCS-191286
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
During the past years, deep packet inspection has been prevalent in network intrusion detection systems. Most solutions employ complex algorithms to analyze the intended behaviour and underlying characteristics of packets and their payloads, in an effort to detect and prevent malicious users and software from communicating over business intranets and wider networks. Still, there are multiple issues that inhibit their success rate. Most signature-based security software is plagued by false positives and/or false negatives. On the other hand, behavioral-based solutions achieve better detection rates but need to analyze large amounts of traffic. In this article, we present a real-time network traffic monitoring system that implements machine learning over side channel characteristics of TCP network packets to distinguish normal from malicious TCP sessions, even when encryption is in place. We test in university networks and test multiple different types of traffic. We show that, our approach (i) requires notably less information to achieve similar (if not better) detection rates, (ii) works over encrypted traffic as well, and (iii) has notably low false positives and false negatives in everyday case study scenarios.
引用
收藏
页码:507 / 520
页数:14
相关论文
共 50 条
  • [41] On the performance of real-time multimedia streaming transmission using TCP
    Xiong Y.
    Wu M.
    Jia W.
    Gaojishu Tongxin/Chinese High Technology Letters, 2011, 21 (10): : 997 - 1002
  • [42] Semantics-Based Online Malware Detection: Towards Efficient Real-Time Protection Against Malware
    Das, Sanjeev
    Liu, Yang
    Zhang, Wei
    Chandramohan, Mahintham
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2016, 11 (02) : 289 - 302
  • [43] End-Edge Coordinated Inference for Real-Time BYOD Malware Detection using Deep Learning
    Tan, Xinrui
    Li, Hongjia
    Wang, Liming
    Xu, Then
    2020 IEEE WIRELESS COMMUNICATIONS AND NETWORKING CONFERENCE (WCNC), 2020,
  • [44] Real-Time GPU-based Timing Channel Detection using Entropy
    Gegan, Ross K.
    Ahuja, Vishal
    Owens, John D.
    Ghosal, Dipak
    2016 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2016, : 296 - 305
  • [45] Improved real-time permission based malware detection and clustering approach using model independent pruning
    Thiyagarajan, Janani
    Akash, A.
    Murugan, Brindha
    IET INFORMATION SECURITY, 2020, 14 (05) : 531 - 541
  • [46] Real-Time Traffic Sign Detection via Color Probability Model and Integral Channel Features
    Yang, Yi
    Wu, Fuchao
    PATTERN RECOGNITION (CCPR 2014), PT II, 2014, 484 : 545 - 554
  • [47] Real-Time Driver-Drowsiness Detection System Using Facial Features
    Deng, Wanghua
    Wu, Ruoxue
    IEEE ACCESS, 2019, 7 : 118727 - 118738
  • [48] Real-Time People Detection in Videos Using Geometrical Features and Adaptive Boosting
    Pedrocca, Pablo Julian
    Allili, Mohand Said
    IMAGE ANALYSIS AND RECOGNITION: 8TH INTERNATIONAL CONFERENCE, ICIAR 2011, PT I, 2011, 6753 : 314 - 324
  • [49] Real-Time DSP Implementation of Pedestrian Detection Algorithm Using HOG Features
    Chavan, Akshay
    Yogamani, Senthil Kumar
    2012 12TH INTERNATIONAL CONFERENCE ON ITS TELECOMMUNICATIONS (ITST-2012), 2012, : 346 - 349
  • [50] Real-Time Lane Region Detection Using a Combination of Geometrical and Image Features
    Hernandez, Danilo Caceres
    Kurnianggoro, Laksono
    Filonenko, Alexander
    Jo, Kang Hyun
    SENSORS, 2016, 16 (11):