Error-Sensor: Mining Information from HTTP Error Traffic for Malware Intelligence

Error-Sensor: Mining Information from HTTP Error Traffic for Malware Intelligence
复制标题

DOI:
10.1007/978-3-030-00470-5_22
复制
发表时间:
2018-09
期刊:
--
影响因子:
--
通讯作者:
Jialong Zhang;Jiyong Jang;G. Gu;M. Stoecklin;Xin Hu
Jialong Zhang;Jiyong Jang;G. Gu;M. Stoecklin;Xin Hu
中科院分区:
其他
文献类型:
--
作者:
Jialong Zhang;Jiyong Jang;G. Gu;M. Stoecklin;Xin Hu

文献摘要

相似文献

恶意软件在发起恶意活动时经常会遇到网络故障,例如连接到已被关闭的受感染服务器、连接到根据企业网络中的访问控制策略而被阻止的恶意服务器,或者扫描/利用易受攻击的网页。为了克服此类故障并提高针对此类故障的恢复能力,恶意软件作者采用了各种策略,例如连接到多个备份服务器或连接到良性服务器以进行初始网络连接检查。这些网络故障和恢复策略导致了本文新发现并深入研究的显着特征。我们注意到,恶意软件引起的网络故障在故障模式和恢复行为模式方面与良性用户/软件引起的故障有很大不同。在本文中,我们介绍了第一个大规模测量研究的结果,该研究根据 HTTP 错误调查了良性用户/软件和恶意软件的不同网络行为。通过检查 16,000 多个客户端生成的超过 100 万条 HTTP 日志,我们识别出源自错误来源模式、错误生成模式和错误恢复模式的恶意活动的强烈指标。基于这些见解,我们设计了一个新系统,Error-Sensor,仅从 HTTP 错误及其周围的成功请求中自动检测恶意软件引起的流量。我们对Error-Sensor在企业网络中收集的大规模真实网络跟踪进行了评估。Error-Sensor以0.005%的误报率实现了99.79%的检测率,以识别恶意软件生成的HTTP错误,并进一步发现现有部署的入侵检测系统未捕获的隐蔽恶意流量(例如恶意软件备份行为)。
Malware often encounters network failures when it launches malicious activities, such as connecting to compromised servers that have been already taken down, connecting to malicious servers that are blocked based on access control policies in enterprise networks, or scanning/exploiting vulnerable web pages. To overcome such failures and improve the resilience in light of such failures, malware authors have employed various strategies, e.g., connecting to multiple backup servers or connecting to benign servers for initial network connectivity checks. These network failures and recovery strategies lead to distinguishing traits, which are newly discovered and thoroughly studied in this paper. We note that network failures caused by malware are quite different from the failures caused by benign users/software in terms of their failure patterns and recovery behavior patterns.In this paper, we present the results of the first large-scale measurement study investigating the different network behaviors of both benign user/software and malware in light of HTTP errors. By inspecting over 1 million HTTP logs generated by over 16,000 clients, we identify strong indicators of malicious activities derived fromerror provenance patterns,error generation patterns, anderror recovery patterns. Based on the insights, we design a new system,Error-Sensor, to automatically detect traffic caused by malware from only HTTP errors and their surrounding successful requests. We evaluateError-Sensoron a large scale of real-world web traces collected in an enterprise network.Error-Sensorachieves a detection rate of 99.79% at a false positive rate of 0.005% to identify HTTP errors generated by malware, and further, spots surreptitious malicious traffic (e.g., malware backup behavior) that was not caught by existing deployed intrusion detection systems.