Malware Beaconing Detection by Mining Large-scale DNS Logs for Targeted Attack Identification

Malware Beaconing Detection by Mining Large-scale DNS Logs for Targeted Attack Identification
复制标题

DOI:
--
复制
发表时间:
2016-03
期刊:
World Academy of Science, Engineering and Technology, International Journal of Computer and Information Engineering
影响因子:
--
通讯作者:
Andrii Shalaginov;K. Franke;Xiongwei Huang
Andrii Shalaginov;K. Franke;Xiongwei Huang
中科院分区:
其他
文献类型:
--
作者:
Andrii Shalaginov;K. Franke;Xiongwei Huang

文献摘要

被引文献

相似文献

当今网络安全的主要问题之一是出现了由对手使用复杂工具进行的有针对性的攻击。这些攻击通常会窃取高级员工的系统权限,以便未经授权访问机密知识和宝贵的知识产权。用于系统初始危害的恶意软件非常复杂,可能针对零日漏洞。在这项工作中,我们利用恶意软件的常见行为称为“信标”,这意味着受感染的主机通信命令和控制服务器在定期的时间间隔,具有相对较小的时间变化。通过被动网络监控分析此类信标活动,可以检测潜在的恶意软件感染。因此,我们专注于时间间隔作为目标企业网络中可能的C2活动的指标。我们将DNS日志文件表示为一个图,其顶点是目的域,边是时间戳。然后,通过使用四个周期性检测算法的每对内部和外部的通信,我们检查时间戳序列,以确定信标活动。最后,根据图的结构,我们推断是否存在其他感染的主机和恶意域注册的攻击活动的关键字-恶意软件检测,网络安全,有针对性的攻击。
One of the leading problems in Cyber Security today is the emergence of targeted attacks conducted by adversaries with access to sophisticated tools. These attacks usually steal senior level employee system privileges, in order to gain unauthorized access to confidential knowledge and valuable intellectual property. Malware used for initial compromise of the systems are sophisticated and may target zero-day vulnerabilities. In this work we utilize common behaviour of malware called ”beacon”, which implies that infected hosts communicate to Command and Control servers at regular intervals that have relatively small time variations. By analysing such beacon activity through passive network monitoring, it is possible to detect potential malware infections. So, we focus on time gaps as indicators of possible C2 activity in targeted enterprise networks. We represent DNS log files as a graph, whose vertices are destination domains and edges are timestamps. Then by using four periodicity detection algorithms for each pair of internal-external communications, we check timestamp sequences to identify the beacon activities. Finally, based on the graph structure, we infer the existence of other infected hosts and malicious domains enrolled in the attack activities Keywords—Malware detection, network security, targeted attack.