CBSeq: A Channel-level Behavior Sequence For Encrypted Malware Traffic Detection

07/18/2023
by   Susu Cui, et al.
0

Machine learning and neural networks have become increasingly popular solutions for encrypted malware traffic detection. They mine and learn complex traffic patterns, enabling detection by fitting boundaries between malware traffic and benign traffic. Compared with signature-based methods, they have higher scalability and flexibility. However, affected by the frequent variants and updates of malware, current methods suffer from a high false positive rate and do not work well for unknown malware traffic detection. It remains a critical task to achieve effective malware traffic detection. In this paper, we introduce CBSeq to address the above problems. CBSeq is a method that constructs a stable traffic representation, behavior sequence, to characterize attacking intent and achieve malware traffic detection. We novelly propose the channels with similar behavior as the detection object and extract side-channel content to construct behavior sequence. Unlike benign activities, the behavior sequences of malware and its variant's traffic exhibit solid internal correlations. Moreover, we design the MSFormer, a powerful Transformer-based multi-sequence fusion classifier. It captures the internal similarity of behavior sequence, thereby distinguishing malware traffic from benign traffic. Our evaluations demonstrate that CBSeq performs effectively in various known malware traffic detection and exhibits superior performance in unknown malware traffic detection, outperforming state-of-the-art methods.

READ FULL TEXT
research
06/10/2019

Malware Detection with LSTM using Opcode Language

Nowadays, with the booming development of Internet and software industry...
research
08/09/2021

Leveraging Uncertainty for Improved Static Malware Detection Under Extreme False Positive Constraints

The detection of malware is a critical task for the protection of comput...
research
01/04/2021

Echelon: Two-Tier Malware Detection for Raw Executables to Reduce False Alarms

Existing malware detection approaches suffer from a simplistic trade-off...
research
06/21/2019

Joint Detection of Malicious Domains and Infected Clients

Detection of malware-infected computers and detection of malicious web d...
research
09/23/2020

Dataset Optimization Strategies for MalwareTraffic Detection

Machine learning is rapidly becoming one of the most important technolog...
research
07/27/2019

Discovering Encrypted Bot and Ransomware Payloads Through Memory Inspection Without A Priori Knowledge

Malware writers frequently try to hide the activities of their agents wi...
research
10/09/2019

An MDL-Based Classifier for Transactional Datasets with Application in Malware Detection

We design a classifier for transactional datasets with application in ma...

Please sign up or login with your details

Forgot password? Click here to reset