Ensemble Clustering for Internet Security Applications

Ensemble Clustering for Internet Security Applications
复制标题

DOI:
10.1109/tsmcc.2012.2222025
复制
发表时间:
2012-11
期刊:
IEEE Transactions on Systems, Man, and Cybernetics, Part C (Applications and Reviews)
影响因子:
--
通讯作者:
Weiwei Zhuang;Yanfang Ye;Yong Chen;Tao Li
Weiwei Zhuang;Yanfang Ye;Yong Chen;Tao Li
中科院分区:
其他
文献类型:
--
作者:
Weiwei Zhuang;Yanfang Ye;Yong Chen;Tao Li

文献摘要

被引文献

相似文献

恶意软件和钓鱼网站的检测由于其对互联网安全的破坏,一直是互联网安全领域备受关注的话题。与恶意软件攻击相比,钓鱼网站诈骗是一种相对较新的网络犯罪。然而,它们有一些共同的性质:1)恶意软件样本和钓鱼网站都是在经济利益的驱动下以每天数千的速度创建的;以及2)以网页内容的词频为代表的钓鱼网站与以程序指令频率为代表的恶意软件样本具有相似的特征。在过去的几年中,许多集群技术被用于自动检测恶意软件和钓鱼网站。在这些技术中,检测过程通常分为两个步骤:1)特征提取,其中提取代表性特征以捕获文件样本或网站的特征;以及2)分类,其中使用智能技术基于对特征表示的计算分析将文件样本或网站自动分组为不同的类别。然而,在实际工业产品中应用的还很少。在本文中,我们开发了一个自动分类系统,通过聚合不同基本聚类算法生成的聚类解决方案,使用聚类集成来自动对钓鱼网站或恶意软件样本进行分组。我们提出了一种原则性的集群集成框架,将基于共识划分的个体集群解决方案结合在一起,不仅适用于恶意软件分类,也适用于钓鱼网站的集群。此外,样本级/网站级约束形式的领域知识可以自然地纳入到集成框架中。通过对大型、真实的日常钓鱼网站和金山软件网络安全实验室恶意软件收集的案例研究,验证了该方法的有效性和高效性。
Due to their damage to Internet security, malware and phishing website detection has been the Internet security topics that are of great interests. Compared with malware attacks, phishing website fraud is a relatively new Internet crime. However, they share some common properties: 1) both malware samples and phishing websites are created at a rate of thousands per day driven by economic benefits; and 2) phishing websites represented by the term frequencies of the webpage content share similar characteristics with malware samples represented by the instruction frequencies of the program. Over the past few years, many clustering techniques have been employed for automatic malware and phishing website detection. In these techniques, the detection process is generally divided into two steps: 1) feature extraction, where representative features are extracted to capture the characteristics of the file samples or the websites; and 2) categorization, where intelligent techniques are used to automatically group the file samples or websites into different classes based on computational analysis of the feature representations. However, few have been applied in real industry products. In this paper, we develop an automatic categorization system to automatically group phishing websites or malware samples using a cluster ensemble by aggregating the clustering solutions that are generated by different base clustering algorithms. We propose a principled cluster ensemble framework to combine individual clustering solutions that are based on the consensus partition, which can not only be applied for malware categorization, but also for phishing website clustering. In addition, the domain knowledge in the form of sample-level/website-level constraints can be naturally incorporated into the ensemble framework. The case studies on large and real daily phishing websites and malware collection from the Kingsoft Internet Security Laboratory demonstrate the effectiveness and efficiency of our proposed method.