HTTP-Based APT Malware Infection Detection Using URL Correlation Analysis

HTTP-Based APT Malware Infection Detection Using URL Correlation Analysis
复制标题

使用 URL 相关性分析进行基于 HTTP 的 APT 恶意软件感染检测

DOI:
10.1155/2021/6653386
复制
发表时间:
2021-04
期刊:
Secur. Commun. Networks
影响因子:
--
通讯作者:
Xiao-Lei Liu
Xiao-Lei Liu
中科院分区:
其他
文献类型:
--
作者:
Weina Niu;Jiao Xie;Xiaosong Zhang;Chong Wang;Xin-Qiang Li;Rui-Dong Chen;Xiao-Lei Liu

文献摘要

参考文献

相似文献

APT Malware利用HTTP与C&C服务器建立通信,以隐藏其恶意活动,可以通过分析HTTP流量来发现基于HTTP的APT恶意软件感染。但是,适用于机器学习,它们从有限的基于HTTP的APT恶意软件数据集中提取的功能太简单了在本文中,我们提出了一种创新的方法,可以通过分析HTTP流量的标头字段来揭示与数据剥落和其他可疑APT活动有关的适当的恶意软件。 Web请求图。剩下的不相关的合法请求。我们使用1.48 GB的方法从Clickminer和280 MB APT APT恶意软件的HTTP流量进行了。检测方法可以正确检测96.08%的APT恶意软件流量,其召回率为98.87%进行了实验,以将我们的方法与江外方法Malhunter和BotDet进行比较,实验结果证实,我们的检测方法的性能更好,其准确性达到96.08%,F1值增加了5%以上。
APT malware exploits HTTP to establish communication with a C & C server to hide their malicious activities. Thus, HTTP-based APT malware infection can be discovered by analyzing HTTP traffic. Recent methods have been dependent on the extraction of statistical features from HTTP traffic, which is suitable for machine learning. However, the features they extract from the limited HTTP-based APT malware traffic dataset are too simple to detect APT malware with strong randomness insufficiently. In this paper, we propose an innovative approach which could uncover APT malware traffic related to data exfiltration and other suspect APT activities by analyzing the header fields of HTTP traffic. We use the Referer field in the HTTP header to construct a web request graph. Then, we optimize the web request graph by combining URL similarity and redirect reconstruction. We also use a normal uncorrelated request filter to filter the remaining unrelated legitimate requests. We have evaluated the proposed method using 1.48 GB normal HTTP flow from clickminer and 280 MB APT malware HTTP flow from Stratosphere Lab, Contagiodump, and pcapanalysis. The experimental results have shown that the URL-correlation-based APT malware traffic detection method can correctly detect 96.08% APT malware traffic, and its recall rate is 98.87%. We have also conducted experiments to compare our approach against Jiang’s method, MalHunter, and BotDet, and the experimental results have confirmed that our detection approach has a better performance, the accuracy of which reached 96.08% and the F1 value increased by more than 5%.
DOI: 10.1109/pst.2014.6890946
发表时间: 2014-07
期刊: 2014 Twelfth Annual International Conference on Privacy, Security and Trust
影响因子: --
作者:
Apostolis Zarras;A. Papadogiannakis;R. Gawlik;Thorsten Holz
通讯作者: Apostolis Zarras;A. Papadogiannakis;R. Gawlik;Thorsten Holz
DOI: 10.1109/dsc.2019.00080
发表时间: 2019-06
期刊: 2019 IEEE Fourth International Conference on Data Science in Cyberspace (DSC)
影响因子: --
作者:
Zhihui Guo;Jin Peng;Jun Fu;Yexia Cheng;Cancan Chen
通讯作者: Zhihui Guo;Jin Peng;Jun Fu;Yexia Cheng;Cancan Chen
DOI: 10.1109/icc.2017.7997372
发表时间: 2017-07
期刊: 2017 IEEE International Conference on Communications (ICC)
影响因子: --
作者:
Sho Mizuno;Mitsuhiro Hatada;Tatsuya Mori;Shigeki Goto
通讯作者: Sho Mizuno;Mitsuhiro Hatada;Tatsuya Mori;Shigeki Goto
DOI: 10.1109/ipccc47392.2019.8958732
发表时间: 2019-10
期刊: 2019 IEEE 38th International Performance Computing and Communications Conference (IPCCC)
影响因子: --
作者:
Jianguo Jiang;Qilei Yin;Zhixin Shi;Meimei Li;Bin Lv
通讯作者: Jianguo Jiang;Qilei Yin;Zhixin Shi;Meimei Li;Bin Lv
DOI: 10.1145/2420950.2420969
发表时间: 2012-12
期刊: --
影响因子: --
作者:
Leyla Bilge;D. Balzarotti;William K. Robertson;E. Kirda;Christopher Krügel
通讯作者: Leyla Bilge;D. Balzarotti;William K. Robertson;E. Kirda;Christopher Krügel