A New C&C Channel Detection Framework Using Heuristic Rule and Transfer Learning

A New C&C Channel Detection Framework Using Heuristic Rule and Transfer Learning
复制标题

DOI:
10.1109/ipccc47392.2019.8958732
复制
发表时间:
2019-10
期刊:
2019 IEEE 38th International Performance Computing and Communications Conference (IPCCC)
影响因子:
--
通讯作者:
Jianguo Jiang;Qilei Yin;Zhixin Shi;Meimei Li;Bin Lv
Jianguo Jiang;Qilei Yin;Zhixin Shi;Meimei Li;Bin Lv
中科院分区:
其他
文献类型:
--
作者:
Jianguo Jiang;Qilei Yin;Zhixin Shi;Meimei Li;Bin Lv

文献摘要

被引文献

相似文献

许多僵尸网络检测方法着重于识别重要的C&C通道。他们中的大多数需要C&C培训设置来建立行为检测模型。但是,当缺乏针对新的或未知的僵尸网络的训练设置时,这些方法可能会变得效率低下甚至无效。要克服它,我们为C&C渠道检测提出了新的一般框架。它既不需要我们知道机器人家族或准备培训集,也不需要部署恶意活动监视器。此外,它也能够从历史数据集中挖掘有用的知识,以提高其检测性能。在我们的框架中,我们提出了一种聚类方法和几种启发式规则,以汇总和标记部分C&C流量,示例选择功能以挖掘有用的历史知识以及基于转移学习的模型,以查找其他C&C渠道。我们在两个数据集上评估了我们的框架,并分别达到了约0.886和0.960的最佳C&C量。此外,比较结果进一步表明其性能优势和更好的行为学习能力。
A great many of botnet detection methods focus on recognizing the significant C&C channels. Most of them require a C&C training set to build a behavior detection model. However, when lacking such training set for new or unknown botnets, these methods may become inefficient or even invalid.To overcome it, we propose a new general framework for C&C channel detection. It neither needs us to know the families of bots or prepare a training set nor requires deploying malicious activity monitors. Also, it is capable of mining useful knowledge from the historical dataset to boost its detection performance. In our framework, we put forward a clustering method and several heuristic rules to aggregate and label partial C&C traffic, a sample selection function to mine useful historical knowledge and a transfer learning based model to find other C&C channels. We evaluated our framework on two datasets and achieved the best C&C F-measure of about 0.886 and 0.960 respectively. Moreover, the comparison result further indicates its performance advantage and better behavior learning ability.