A method based on hierarchical spatiotemporal features for trojan traffic detection

09/03/2023
by   Jiang Xie, et al.
0

Trojans are one of the most threatening network attacks currently. HTTP-based Trojan, in particular, accounts for a considerable proportion of them. Moreover, as the network environment becomes more complex, HTTP-based Trojan is more concealed than others. At present, many intrusion detection systems (IDSs) are increasingly difficult to effectively detect such Trojan traffic due to the inherent shortcomings of the methods used and the backwardness of training data. Classical anomaly detection and traditional machine learning-based (TML-based) anomaly detection are highly dependent on expert knowledge to extract features artificially, which is difficult to implement in HTTP-based Trojan traffic detection. Deep learning-based (DL-based) anomaly detection has been locally applied to IDSs, but it cannot be transplanted to HTTP-based Trojan traffic detection directly. To solve this problem, in this paper, we propose a neural network detection model (HSTF-Model) based on hierarchical spatiotemporal features of traffic. Meanwhile, we combine deep learning algorithms with expert knowledge through feature encoders and statistical characteristics to improve the self-learning ability of the model. Experiments indicate that F1 of HSTF-Model can reach 99.4 present a dataset BTHT consisting of HTTP-based benign and Trojan traffic to facilitate related research in the field.

READ FULL TEXT
research
09/07/2023

Detecting unknown HTTP-based malicious communication behavior via generated adversarial flows and hierarchical traffic features

Malicious communication behavior is the network communication behavior g...
research
08/03/2021

HTTP2vec: Embedding of HTTP Requests for Detection of Anomalous Traffic

Hypertext transfer protocol (HTTP) is one of the most widely used protoc...
research
09/07/2023

HSTF-Model: an HTTP-based Trojan Detection Model via the Hierarchical Spatio-Temporal Features of Traffics

HTTP-based Trojan is extremely threatening, and it is difficult to be ef...
research
10/27/2020

Construction of Two Statistical Anomaly Features for Small-Sample APT Attack Traffic Classification

Advanced Persistent Threat (APT) attack, also known as directed threat a...
research
05/14/2022

Unsupervised Abnormal Traffic Detection through Topological Flow Analysis

Cyberthreats are a permanent concern in our modern technological world. ...
research
03/27/2019

Botnet fingerprinting method based on anomaly detection in SMTP conversations

The paper presents the results obtained during research on detection of ...
research
05/01/2022

Federated Semi-Supervised Classification of Multimedia Flows for 3D Networks

Automatic traffic classification is increasingly becoming important in t...

Please sign up or login with your details

Forgot password? Click here to reset