M3F: A novel multi-session and multi-protocol based malware traffic fingerprinting

计算机科学 会话(web分析) 恶意软件 协议(科学) 计算机安全 计算机网络 网络数据包 医学 替代医学 病理 万维网
作者
Jian Liu,Qingsai Xiao,Liling Xin,Qiuyun Wang,Yepeng Yao,Zhengwei Jiang
出处
期刊:Computer Networks [Elsevier]
卷期号:227: 109723-109723
标识
DOI:10.1016/j.comnet.2023.109723
摘要

In recent years, cyber attacks have become increasingly frequent, which has had a tremendous negative impact on public life and social order. Accurately and quickly finding malware traffic from massive network traffic is one of the keys to defending against network attacks. Traditional detection methods, whether signature-based or machine learning-based, use a packet or a session as the smallest detection unit. Usually, malware creates more than one session while executing malicious functions. Detecting these sessions alone without contextual information is prone to false negatives and false positives. To address these problems, we propose M3F, a Multi-session and Multi-protocol based Malware traffic Fingerprinting that uses multiple related sessions with different protocols as the smallest classification unit. We associate multiple sessions of different protocols together to form several session sequences. For each session in a session sequence, we represent it with a state with three features so that a session sequence can be transformed into a state sequence. For a malware family, we learn a first-order homogeneous Markov chain using its state sequences as its traffic fingerprint (aka M3F). M3Fs reflect the dynamics of malware communication traffic. Meanwhile, the approximate matching technique is used to deal with the evolution of malware, which can improve the recall rate. Armed with M3F, we can locate malware traffic in massive network traffic. We use a large amount of malicious traffic to verify M3F. The experimental results show that M3F has 99.41% precision and 99.54% recall, both outperforming the baseline methods. It does not mark normal traffic as malicious traffic. Additionally, M3F is well interpretable and is the network-level representation of the malware’s behavior.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
冰山未闯发布了新的文献求助10
1秒前
丘比特应助瑶yao采纳,获得10
2秒前
grs完成签到 ,获得积分10
3秒前
秦桂敏完成签到 ,获得积分10
3秒前
3秒前
研友_VZG7GZ应助帅气的夏天采纳,获得10
3秒前
传奇3应助外向访卉采纳,获得10
5秒前
5秒前
纸包鱼发布了新的文献求助30
5秒前
wz发布了新的文献求助10
6秒前
N252WN发布了新的文献求助10
6秒前
why完成签到,获得积分10
6秒前
机灵的雪糕完成签到,获得积分10
6秒前
赘婿应助axunQAQ采纳,获得10
6秒前
7秒前
123应助甘sir采纳,获得10
7秒前
科研通AI6.2应助hugeyoung采纳,获得10
7秒前
科研通AI6.1应助hugeyoung采纳,获得10
7秒前
科研通AI6.2应助hugeyoung采纳,获得10
8秒前
科研通AI6.1应助hugeyoung采纳,获得50
8秒前
wes5566发布了新的文献求助10
8秒前
8秒前
Orange应助早日毕业采纳,获得10
9秒前
9秒前
10秒前
10秒前
why发布了新的文献求助10
10秒前
传奇3应助micpeach采纳,获得10
10秒前
素笺发布了新的文献求助10
11秒前
11秒前
Akim应助枕风采纳,获得10
12秒前
李盈盈发布了新的文献求助10
12秒前
13秒前
爆米花应助居里姐姐采纳,获得30
13秒前
13秒前
Soul459发布了新的文献求助10
14秒前
1111发布了新的文献求助10
14秒前
纸包鱼完成签到,获得积分10
15秒前
15秒前
15秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Kinesiophobia : a new view of chronic pain behavior 3000
3O - Innate resistance in EGFR mutant non-small cell lung cancer (NSCLC) patients by coactivation of receptor tyrosine kinases (RTKs) 1000
Molecular Biology of Cancer: Mechanisms, Targets, and Therapeutics 900
Signals, Systems, and Signal Processing 510
Discrete-Time Signals and Systems 510
Proceedings of the Fourth International Congress of Nematology, 8-13 June 2002, Tenerife, Spain 500
热门求助领域 (近24小时)
化学 材料科学 生物 医学 工程类 计算机科学 有机化学 物理 生物化学 纳米技术 复合材料 内科学 化学工程 人工智能 催化作用 遗传学 数学 基因 量子力学 物理化学
热门帖子
关注 科研通微信公众号,转发送积分 5933576
求助须知:如何正确求助?哪些是违规求助? 7003063
关于积分的说明 15855604
捐赠科研通 5062241
什么是DOI,文献DOI怎么找? 2722899
邀请新用户注册赠送积分活动 1680338
关于科研通互助平台的介绍 1610713