PORTFILER: Port-Level Network Profiling for Self-Propagating Malware Detection

PORTFILER: Port-Level Network Profiling for Self-Propagating Malware Detection
复制标题

DOI:
10.1109/cns53000.2021.9705045
复制
发表时间:
2021-10
期刊:
2021 IEEE Conference on Communications and Network Security (CNS)
影响因子:
--
通讯作者:
Talha Ongun;Oliver Spohngellert;Benjamin Miller;Simona Boboila;Alina Oprea;Tina Eliassi-Rad;Jason Hiser;Alastair Nottingham;J. Davidson;M. Veeraraghavan
Talha Ongun;Oliver Spohngellert;Benjamin Miller;Simona Boboila;Alina Oprea;Tina Eliassi-Rad;Jason Hiser;Alastair Nottingham;J. Davidson;M. Veeraraghavan
中科院分区:
其他
文献类型:
--
作者:
Talha Ongun;Oliver Spohngellert;Benjamin Miller;Simona Boboila;Alina Oprea;Tina Eliassi-Rad;Jason Hiser;Alastair Nottingham;J. Davidson;M. Veeraraghavan

文献摘要

相似文献

最近的自传播恶意软件(SPM)活动危害了互联网上数十万台受害机器。在早期阶段检测这些攻击是具有挑战性的,因为对手利用常见的网络服务,使用新技术,并可以逃避现有的检测机制。我们提出了PortFILER(端口级网络流量ProFILER),一个新的机器学习系统应用于网络流量检测SPM攻击。PORTFILER从在受监控网络边界收集的Zeek连接日志中提取端口级特征,应用异常检测技术来识别可疑事件,并对跨端口的警报进行排名,以供安全运营中心(SOC)进行调查。我们提出了一种新的集成方法来聚合PORTFILER中的各个模型,与标准ML基线相比,该方法可以提高对几种规避策略的弹性。我们广泛评估PortFILER从两个大学网络收集的流量,并表明它可以检测不同模式的SPM攻击,如WannaCry和米拉伊,并在规避下表现良好。跨端口的排名在排名最高的100个警报中实现了超过0.94的精度和低于8 × 10^{-4}$的误报率。当部署在大学网络上时,PortFILER在其中一个校园网络上检测到异常的类似SPM的活动,并被大学SOC确认为恶意活动。PortFILER还检测到在两所大学网络上重新创建的米拉伊攻击,其精确度和召回率高于基于深度学习的自动编码器方法。
Recent self-propagating malware (SPM) campaigns compromised hundred of thousands of victim machines on the Internet. It is challenging to detect these attacks in their early stages, as adversaries utilize common network services, use novel techniques, and can evade existing detection mechanisms. We propose PorTFILER (PORT-Level Network Traffic ProFILER), a new machine learning system applied to network traffic for detecting SPM attacks. PORTFILER extracts port-level features from the Zeek connection logs collected at a border of a monitored network, applies anomaly detection techniques to identify suspicious events, and ranks the alerts across ports for investigation by the Security Operations Center (SOC). We propose a novel ensemble methodology for aggregating individual models in PORTFILER that increases resilience against several evasion strategies compared to standard ML baselines. We extensively evaluate PorTFILER on traffic collected from two university networks, and show that it can detect SPM attacks with different patterns, such as WannaCry and Mirai, and performs well under evasion. Ranking across ports achieves precision over 0.94 and false positive rates below $8 \times 10^{-4}$ in the top 100 highly ranked alerts. When deployed on the university networks, PorTFILER detected anomalous SPM-like activity on one of the campus networks, confirmed by the university SOC as malicious. PortFILER also detected a Mirai attack recreated on the two university networks with higher precision and recall than deep-learning based autoencoder methods.