Fast and Accurate Machine Learning-based Malware Detection via RC4 Ciphertext Analysis*
Fast and Accurate Machine Learning-based Malware Detection via RC4 Ciphertext Analysis*
复制标题
通过 RC4 密文分析进行快速、准确的基于机器学习的恶意软件检测*
DOI:
--
复制
发表时间:
2019
期刊:
影响因子:
--
通讯作者:
Mingon Kang
中科院分区:
文献类型:
--
作者:
Junggab Son;Euiseong Ko;Uday Bhaskar Boyanapalli;Donghyun Kim;Youngsoon Kim;Mingon Kang
Recent malware increases its viability by employing ciphers which help to hide malicious intention and/or behavior against detection schemes. So far, many efforts have been made to detect malware and to prevent it from damaging clients by monitoring network packets. However, these conventional detection schemes tend to treat an encrypted packet as legitimate due to the hardness of extracting information from ciphertexts. Cryptoanalysis of each packet flowing over a network might be one feasible solution to the problem. However, this approach is computationally expensive and lacks accuracy, and thus it is consequently not a practical solution. To address the problem, we firstly introduce a discovery that a fixed encryption key generates unique statistical patterns on RC4 ciphertexts. To the best of our knowledge, this unique signature has never been discussed in the literature. Then, we propose a machine learning-based detection scheme that can identify malware packets efficiently and accurately by leveraging the discovery. The proposed scheme directly analyze network packets without decrypting ciphertexts. Moreover, our analysis demonstrates the proposed scheme requires only a tiny subset of the network packet.
DOI:
10.1109/euvip.2014.7018361
发表时间:
2014
期刊:
--
影响因子:
--
作者:
Burgess C
通讯作者:
Burgess C