Uncovering APT malware traffic using deep learning combined with time sequence and association analysis

Uncovering APT malware traffic using deep learning combined with time sequence and association analysis
复制标题

利用深度学习结合时序和关联分析发现 APT 恶意软件流量

DOI:
10.1016/j.cose.2022.102809
复制
发表时间:
2022-06
期刊:
Elsevier
影响因子:
--
通讯作者:
Cheng Huang
Cheng Huang
中科院分区:
其他
文献类型:
--
作者:
Niu Weina;Jie Zhou;Yibin Zhao;Xiaosong Zhang;Yujie Peng;Cheng Huang

文献摘要

相似文献

传统的基于静态流量特征和机器学习的恶意软件检测方法难以科普日益增多的APT恶意软件变种。为了缓解这一问题,本文提出了一种基于深度学习的恶意软件分类方法,该方法结合了时间序列特征和关联规则特征。该方法采用改进的LSTM神经网络结构RESNET_LSTM和PARALLEL_LSTM,提取不同协议流量的时序特征。它还利用关联分析来生成定量规则特征。最后,我们将时间序列特征向量和量化规则向量作为输入连接到深度学习模型,以检测恶意软件流量。我们在一个由57种恶意软件生成的恶意流量和正常流量组成的数据集上评估了我们提出的方法。实验结果表明,在训练阶段,PARALLEL_LSTM结构的损失下降速度比LSTM和RESNET_LSTM结构快。当使用RESNET_LSTM结构时,预测准确度接近100%,这略高于其他两种结构。本文提出的检测方法的准确率均在96%以上,而结合静态流量特征和机器学习的恶意软件检测方法的准确率约为85%。
Traditional malware detection methods based on static traffic characteristics and machine learning are hard to cope with the increasing number of APT malware variants. In order to alleviate this problem, this paper proposes a deep-learning-based malware classification approach that combines time sequence features and association rules features. This method uses the improved LSTM neural network structure named RESNET_LSTM and PARALLEL_LSTM to extract time sequence features of different protocol traffic. It also utilizes association analysis to generate quantitative rule features. Finally, we connect the time sequence feature vector and the quantization rule vector as input to deep learning models to detect malware traffic. We evaluated our proposed approach on a dataset consisting of malicious traffic generated by 57 types of malware and normal traffic. The experimental results demonstrate that the loss decline rate of PARALLEL_LSTM structure during the training phase is faster than that of the LSTM and RESNET_LSTM structures. When the RESNET_LSTM structure is used, the prediction accuracy is close to 100%, which is slightly higher than the other two structures. The accuracy of the detection methods proposed in this paper are all above 96%, while the accuracy of malware detection methods combined with static traffic characteristics and machine learning is about 85%.