Detecting Malicious URLs: A Semi-Supervised Machine Learning System Approach

Detecting Malicious URLs: A Semi-Supervised Machine Learning System Approach
复制标题

检测恶意 URL:半监督机器学习系统方法

DOI:
--
复制
发表时间:
2016
期刊:
Symposium on Symbolic and Numeric Algorithms for Scientific Computing
影响因子:
--
通讯作者:
Adrian
Adrian
中科院分区:
--
文献类型:
--
作者:
A. Gabriel;Dragos Gavrilut;Baetu Ioan Alexandru;Adrian

文献摘要

被引文献

相似文献

随着恶意软件行业的发展,感染计算机或设备的手段也在发展。最常见的传染媒介之一是使用互联网作为切入点。这种方法不仅易于使用,而且由于URL具有不同的形式和形状,因此很难区分恶意URL和良性URL。此外,每个尝试分类或检测URL的系统都必须在真实的时间流上工作,并且需要为提交用于分析的每个URL提供快速响应(在我们的上下文中,快速响应意味着小于300-400毫秒/URL)。从恶意软件创建者的角度来看,在一天内多次更改此类URL确实很容易。一般来说,恶意URL的寿命往往很短(它们出现,提供恶意内容几个小时,然后通常由它们所在的ISP关闭)。本文的目的是提出一个系统,分析网络流量中的URL,也能够调整其检测模型,以适应新的恶意内容。每个正确分类的URL都被重新用作新数据集的一部分,该数据集充当新检测模型的主干。该系统还使用不同的聚类技术,以识别恶意URL上缺乏的功能,从而创建一种方法来改进对此类威胁的检测。
As malware industry grows, so does the means of infecting a computer or device evolve. One of the most common infection vector is to use the Internet as an entry point. Not only that this method is easy to use, but due to the fact that URLs come in different forms and shapes, it is really difficult to distinguish a malicious URL from a benign one. Furthermore, every system that tries to classify or detect URLs must work on a real time stream and needs to provide a fast response for every URL that is submitted for analysis (in our context a fast response means less than 300-400 milliseconds/URL). From a malware creator point of view, it is really easy to change such URLs multiple times in one day. As a general observation, malicious URLs tend to have a short life (they appear, serve malicious content for several hours and then they are shut down usually by the ISP where they reside in). This paper aims to present a system that analyzes URLs in network traffic that is also capable of adjusting its detection models to adapt to new malicious content. Every correctly classified URL is reused as part of a new dataset that acts as the backbone for new detection models. The system also uses different clustering techniques in order to identify the lack of features on malicious URLs, thus creating a way to improve detection for this kind of threats.