M3F: A novel multi-session and multi-protocol based malware traffic fingerprinting

计算机科学 会话(web分析) 恶意软件 协议(科学) 计算机安全 计算机网络 网络数据包 医学 替代医学 病理 万维网
作者
Jian Liu,Qingsai Xiao,Liling Xin,Qiuyun Wang,Yepeng Yao,Zhengwei Jiang
出处
期刊:Computer Networks [Elsevier]
卷期号:227: 109723-109723
标识
DOI:10.1016/j.comnet.2023.109723
摘要

In recent years, cyber attacks have become increasingly frequent, which has had a tremendous negative impact on public life and social order. Accurately and quickly finding malware traffic from massive network traffic is one of the keys to defending against network attacks. Traditional detection methods, whether signature-based or machine learning-based, use a packet or a session as the smallest detection unit. Usually, malware creates more than one session while executing malicious functions. Detecting these sessions alone without contextual information is prone to false negatives and false positives. To address these problems, we propose M3F, a Multi-session and Multi-protocol based Malware traffic Fingerprinting that uses multiple related sessions with different protocols as the smallest classification unit. We associate multiple sessions of different protocols together to form several session sequences. For each session in a session sequence, we represent it with a state with three features so that a session sequence can be transformed into a state sequence. For a malware family, we learn a first-order homogeneous Markov chain using its state sequences as its traffic fingerprint (aka M3F). M3Fs reflect the dynamics of malware communication traffic. Meanwhile, the approximate matching technique is used to deal with the evolution of malware, which can improve the recall rate. Armed with M3F, we can locate malware traffic in massive network traffic. We use a large amount of malicious traffic to verify M3F. The experimental results show that M3F has 99.41% precision and 99.54% recall, both outperforming the baseline methods. It does not mark normal traffic as malicious traffic. Additionally, M3F is well interpretable and is the network-level representation of the malware’s behavior.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
更新
大幅提高文件上传限制,最高150M (2024-4-1)

科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
xiejuan完成签到,获得积分10
1秒前
元澜完成签到 ,获得积分10
4秒前
MMP完成签到,获得积分10
4秒前
豆子发布了新的文献求助10
4秒前
4秒前
347发布了新的文献求助10
6秒前
快乐咸鱼完成签到 ,获得积分10
8秒前
skippy完成签到 ,获得积分10
8秒前
刘梦完成签到,获得积分10
9秒前
噜噜噜发布了新的文献求助10
10秒前
mylaodao完成签到,获得积分0
11秒前
在水一方应助豆子采纳,获得10
11秒前
14秒前
李爱国应助Justice采纳,获得10
14秒前
聪慧世界完成签到,获得积分10
17秒前
18秒前
54132123完成签到,获得积分10
18秒前
噜噜噜完成签到,获得积分10
18秒前
豆子完成签到,获得积分10
19秒前
19秒前
lemon完成签到,获得积分10
24秒前
Tumbleweed668发布了新的文献求助30
26秒前
小星星完成签到 ,获得积分10
27秒前
王老大完成签到,获得积分10
27秒前
滴滴嘟完成签到,获得积分10
28秒前
28秒前
花卷完成签到 ,获得积分10
28秒前
an慧儿发布了新的文献求助10
29秒前
30秒前
cctv18应助噜噜噜采纳,获得10
30秒前
32秒前
王老大发布了新的文献求助10
33秒前
SciGPT应助聪慧世界采纳,获得10
33秒前
34秒前
CJZ完成签到,获得积分10
35秒前
37秒前
37秒前
包子凯越完成签到,获得积分10
38秒前
effortless发布了新的文献求助10
41秒前
41秒前
高分求助中
One Man Talking: Selected Essays of Shao Xunmei, 1929–1939 1000
Yuwu Song, Biographical Dictionary of the People's Republic of China 700
[Lambert-Eaton syndrome without calcium channel autoantibodies] 520
Sphäroguß als Werkstoff für Behälter zur Beförderung, Zwischen- und Endlagerung radioaktiver Stoffe - Untersuchung zu alternativen Eignungsnachweisen: Zusammenfassender Abschlußbericht 500
少脉山油柑叶的化学成分研究 430
Lung resection for non-small cell lung cancer after prophylactic coronary angioplasty and stenting: short- and long-term results 400
Revolutions 400
热门求助领域 (近24小时)
化学 材料科学 医学 生物 有机化学 工程类 生物化学 纳米技术 物理 内科学 计算机科学 化学工程 复合材料 遗传学 基因 物理化学 催化作用 电极 光电子学 量子力学
热门帖子
关注 科研通微信公众号,转发送积分 2452782
求助须知:如何正确求助?哪些是违规求助? 2125043
关于积分的说明 5410551
捐赠科研通 1853976
什么是DOI,文献DOI怎么找? 922092
版权声明 562297
科研通“疑难数据库(出版商)”最低求助积分说明 493297