Joint Detection of Malicious Domains and Infected Clients

06/21/2019
by   Paul Prasse, et al.
0

Detection of malware-infected computers and detection of malicious web domains based on their encrypted HTTPS traffic are challenging problems, because only addresses, timestamps, and data volumes are observable. The detection problems are coupled, because infected clients tend to interact with malicious domains. Traffic data can be collected at a large scale, and antivirus tools can be used to identify infected clients in retrospect. Domains, by contrast, have to be labeled individually after forensic analysis. We explore transfer learning based on sluice networks; this allows the detection models to bootstrap each other. In a large-scale experimental study, we find that the model outperforms known reference models and detects previously unknown malware, previously unknown malware families, and previously unknown malicious domains.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
03/26/2021

ShellCore: Automating Malicious IoT Software Detection by Using Shell Commands Representation

The Linux shell is a command-line interpreter that provides users with a...
research
09/04/2019

HinDom: A Robust Malicious Domain Detection System based on Heterogeneous Information Network with Transductive Classification

Domain name system (DNS) is a crucial part of the Internet, yet has been...
research
02/16/2018

WebEye - Automated Collection of Malicious HTTP Traffic

With malware detection techniques increasingly adopting machine learning...
research
05/18/2022

Analysing and strengthening OpenWPM's reliability

Automated browsers are widely used to study the web at scale. Their prem...
research
07/18/2023

CBSeq: A Channel-level Behavior Sequence For Encrypted Malware Traffic Detection

Machine learning and neural networks have become increasingly popular so...
research
10/22/2020

Malware Traffic Classification: Evaluation of Algorithms and an Automated Ground-truth Generation Pipeline

Identifying threats in a network traffic flow which is encrypted is uniq...
research
09/07/2023

Detecting unknown HTTP-based malicious communication behavior via generated adversarial flows and hierarchical traffic features

Malicious communication behavior is the network communication behavior g...

Please sign up or login with your details

Forgot password? Click here to reset