RADAR: Effective Network-based Malware Detection based on the MITRE ATT CK Framework

12/07/2022
by   Yashovardhan Sharma, et al.
0

MITRE ATT CK is a widespread ontology that specifies tactics, techniques, and procedures (TTPs) typical of malware behaviour, making it possible to exploit such TTPs for malware identification. However, this is far from being an easy task given that benign usage of software can also match some of these TTPs. In this paper, we present RADAR, a system that can identify malicious behaviour in network traffic in two stages: first, RADAR extracts MITRE ATT CK TTPs from arbitrary network traffic captures, and, secondly, it deploys decision trees to differentiate between malicious and benign uses of the detected TTPs. In order to evaluate RADAR, we created a dataset comprising of 2,286,907 malicious and benign samples, for a total of 84,792,452 network flows. The experimental analysis confirms that RADAR is able to (i) match samples to multiple different TTPs, and (ii) effectively detect malware with an AUC score of 0.868. Beside being effective, RADAR is also highly configurable, interpretable, privacy preserving, efficient and can be easily integrated with existing security infrastructure to complement their capabilities.

READ FULL TEXT
research
06/01/2021

MalPhase: Fine-Grained Malware Detection Using Network Flow Data

Economic incentives encourage malware authors to constantly develop new,...
research
03/26/2021

ShellCore: Automating Malicious IoT Software Detection by Using Shell Commands Representation

The Linux shell is a command-line interpreter that provides users with a...
research
10/04/2020

IoT Malware Network Traffic Classification using Visual Representation and Deep Learning

With the increase of IoT devices and technologies coming into service, M...
research
09/08/2021

Unsupervised Detection and Clustering of Malicious TLS Flows

Malware abuses TLS to encrypt its malicious traffic, preventing examinat...
research
10/01/2019

An Analysis of Malware Trends in Enterprise Networks

We present an empirical and large-scale analysis of malware samples capt...
research
03/05/2021

NF-GNN: Network Flow Graph Neural Networks for Malware Detection and Classification

Malicious software (malware) poses an increasing threat to the security ...
research
02/07/2019

Dual-task agent for run-time classification and killing of malicious processes

Malicious software (malware) is one of the key vectors for cyber crimina...

Please sign up or login with your details

Forgot password? Click here to reset