Automated generation of models for fast and precise detection of HTTP-based malware

Automated generation of models for fast and precise detection of HTTP-based malware
复制标题

DOI:
10.1109/pst.2014.6890946
复制
发表时间:
2014-07
期刊:
2014 Twelfth Annual International Conference on Privacy, Security and Trust
影响因子:
--
通讯作者:
Apostolis Zarras;A. Papadogiannakis;R. Gawlik;Thorsten Holz
Apostolis Zarras;A. Papadogiannakis;R. Gawlik;Thorsten Holz
中科院分区:
其他
文献类型:
--
作者:
Apostolis Zarras;A. Papadogiannakis;R. Gawlik;Thorsten Holz

文献摘要

被引文献

相似文献

恶意软件,尤其是僵尸网络是互联网上最重要的安全威胁之一。因此,对这种威胁的准确和及时发现非常重要。由于易于部署,检测通过网络级别识别其恶意活动的机器是一种吸引人的方法。如今,攻击者用于控制感染机器的最常见通信渠道是基于HTTP协议。为了逃避检测,基于HTTP的恶意软件将其行为调整为良性HTTP客户端(例如Web浏览器)的通信模式。这对现有的检测方法构成了重大挑战,例如基于签名和基于行为的检测系统。在本文中,我们提出了Tobound:一种在网络级别准确检测基于HTTP的恶意软件的新方法。关键的想法是,不同实体对HTTP协议的实现具有很小但可感知的差异。在此观察基础上,Tobound自动生成用于恶意和良性请求的模型,并实时分类受监视网络的HTTP流量。我们的评估结果表明,Tobound在识别基于HTTP的僵尸网络方面的表现要优于先前的工作,能够检测到基于HTTP的许多现实HTTP的恶意软件,包括针对目标攻击中使用的高级持久威胁,分类错误的比例很低。
Malicious software and especially botnets are among the most important security threats in the Internet. Thus, the accurate and timely detection of such threats is of great importance. Detecting machines infected with malware by identifying their malicious activities at the network level is an appealing approach, due to the ease of deployment. Nowadays, the most common communication channels used by attackers to control the infected machines are based on the HTTP protocol. To evade detection, HTTP-based malware adapt their behavior to the communication patterns of the benign HTTP clients, such as web browsers. This poses significant challenges to existing detection approaches like signature-based and behavioral-based detection systems. In this paper, we propose BOTHOUND: a novel approach to precisely detect HTTP-based malware at the network level. The key idea is that implementations of the HTTP protocol by different entities have small but perceivable differences. Building on this observation,BOTHOUND automatically generates models for malicious and benign requests and classifies at real time the HTTP traffic of a monitored network. Our evaluation results demonstrate that BOTHOUND outperforms prior work on identifying HTTP-based botnets, being able to detect a large variety of real-world HTTP-based malware, including advanced persistent threats used in targeted attacks, with a very low percentage of classification errors.