Malware on Internet of UAVs Detection Combining String Matching and Fourier Transformation
Malware on Internet of UAVs Detection Combining String Matching and Fourier Transformation
复制标题
字符串匹配与傅里叶变换相结合的无人机互联网恶意软件检测
DOI:
10.1109/jiot.2020.3029970
复制
发表时间:
2021-06
影响因子:
10.6
通讯作者:
Mohsen Guizani
中科院分区:
文献类型:
--
作者:
Weina Niu;Jian'An Xiao;Xiyue Zhang;Xiaosong Zhang;Xiaojiang Du;Xiaoming Huang;Mohsen Guizani
Advanced persistent threat (APT), with intense penetration, long duration, and high customization, has become one of the most grievous threats to cybersecurity. Furthermore, the design and development of Internet-of-Things (IoT) devices often do not focus on security, leading APT to extend to IoT, such as the Internet of emerging unmanned aerial vehicles (UAVs). Whether malware with attack payload can be successfully implanted into UAVs or not is the key to APT on the Internet of UAVs. APT malware on UAVs establishes communication with the command and control (C&C) server to achieve remote control for UAVs-aware information stealing. Existing effective methods detect malware by analyzing malicious behaviors generated during C&C communication. However, APT malware usually adopts a low-traffic attack mode, a large amount of normal traffic is mixed in each attack step, to avoid virus checking and killing. Therefore, it is difficult for traditional malware detection methods to discover APT malware on UAVs that carry weak abnormal signals. Fortunately, we found that most APT attacks use domain name system (DNS) to locate C&C server of malware for information transmission periodically. This behavior will leave some records in the network flow and DNS logs, which provides us with an opportunity to identify infected internal UAVs and external malicious domain names. This article proposes an APT malware on the Internet of UAVs detection method combining string matching and Fourier transformation based on DNS traffic, which is able to handle encrypted and obfuscated traffic due to packet payloads independence. We preprocessed the collected network traffic by converting DNS timestamps of DNS request to strings and used the trained random forest model to discover APT malware domain names based on features extracted through string-matching-based periodicity detection and Fourier transformation-based periodicity detection. The proposed method has been evaluated on the data set, including part of normal domains from the normal traffic and malicious domains marked by security experts from APT malware traffic. Experimental results have shown that our proposed detection method can achieve the accuracy of 94%, which is better than the periodicity detection algorithm alone. Moreover, the proposed method does not need to set the confidence to filter the periodicity with high confidence.
登录
查看更多内容
DOI:
10.1109/icdm.2005.152
发表时间:
2005-11
期刊:
Fifth IEEE International Conference on Data Mining (ICDM'05)
影响因子:
--
作者:
Mohamed G. Elfeky;W. Aref;A. Elmagarmid
通讯作者:
Mohamed G. Elfeky;W. Aref;A. Elmagarmid
DOI:
10.1109/cits.2019.8862148
发表时间:
2019-08
期刊:
2019 International Conference on Computer, Information and Telecommunication Systems (CITS)
影响因子:
--
作者:
Menaka Pushpa Arthur
通讯作者:
Menaka Pushpa Arthur
DOI:
10.1109/icton.2018.8473952
发表时间:
2018-07
期刊:
2018 20th International Conference on Transparent Optical Networks (ICTON)
影响因子:
--
作者:
Nihel Ramdhan;M. Sliti;N. Boudriga
通讯作者:
Nihel Ramdhan;M. Sliti;N. Boudriga
DOI:
--
发表时间:
2016-03
期刊:
World Academy of Science, Engineering and Technology, International Journal of Computer and Information Engineering
影响因子:
--
作者:
Andrii Shalaginov;K. Franke;Xiongwei Huang
通讯作者:
Andrii Shalaginov;K. Franke;Xiongwei Huang
DOI:
10.1007/978-3-319-11379-1_1
发表时间:
2014-09
期刊:
--
影响因子:
--
作者:
Marc Kührer;C. Rossow;Thorsten Holz
通讯作者:
Marc Kührer;C. Rossow;Thorsten Holz