ME-Box: A reliable method to detect malicious encrypted traffic
ME-Box: A reliable method to detect malicious encrypted traffic
复制标题
ME-Box:检测恶意加密流量的可靠方法
DOI:
10.1016/j.jisa.2021.102823
复制
发表时间:
2021
影响因子:
5.6
通讯作者:
Zhu Haiting
中科院分区:
文献类型:
--
作者:
Xu Bingfeng;He gaofeng;Zhu Haiting
Currently, encryption (such as the Transport Layer Security protocol) is used by increasingly more network applications to protect their security and privacy, while it also benefits network attackers who can encrypt their traffic to evade detection. The detection of malicious encrypted traffic is becoming a critical task for cyber security. To accomplish this task, researchers have proposed several enlightening methods, including decryption followed by deep packet inspection (DPI), direct DPI on ciphertext and identification by machine learning algorithms. However, due to privacy violations or performance limitations, the state-of-the-art is far from satisfactory.In this paper, we propose a novel framework and system called ME-Box (Machine learning and Evidence verification) for reliable detection of malicious encrypted traffic. ME-Box has middleboxes deployed in the network and agents installed on the sending hosts. Middleboxes first evaluate the trust degrees of encrypted flows bymachine learningmethods. If some flows are classified as suspicious, then middleboxes provideevidenceof the evaluation results and request the corresponding session-keys from the agents. The agents verify the evidence, and if it is convincing, respond with the correct session-keys. With the session-keys, middleboxes finally decrypt the suspected encrypted flows and perform conventional DPI using intrusion signatures. We implement a prototype system of ME-Box and test it with real malware traffic. The experimental results show that ME-Box requires no modification of current cryptographic protocols and keeps end-users’ privacy well, and its performance is practically deployable.
登录
查看更多内容
DOI:
10.1145/2996758.2996768
发表时间:
2016-10
期刊:
Proceedings of the 2016 ACM Workshop on Artificial Intelligence and Security
影响因子:
--
作者:
Blake Anderson;D. McGrew
通讯作者:
Blake Anderson;D. McGrew
DOI:
10.1007/978-3-319-46301-8_23
发表时间:
2016-09
期刊:
--
影响因子:
--
作者:
T. Kovanen;G. David;T. Hämäläinen
通讯作者:
T. Kovanen;G. David;T. Hämäläinen
DOI:
10.1109/pimrc.2017.8292316
发表时间:
2017-10
期刊:
2017 IEEE 28th Annual International Symposium on Personal, Indoor, and Mobile Radio Communications (PIMRC)
影响因子:
--
作者:
Yun-Chun Chen;Yu-Jhe Li;Aragorn Tseng;Tsungnan Lin
通讯作者:
Yun-Chun Chen;Yu-Jhe Li;Aragorn Tseng;Tsungnan Lin
影响因子:
5.6
作者:
Aceto, Giuseppe;Ciuonzo, Domenico;Pescape, Antonio
通讯作者:
Pescape, Antonio
DOI:
10.1145/3292006.3300025
发表时间:
2018-05
期刊:
Proceedings of the Ninth ACM Conference on Data and Application Security and Privacy
影响因子:
--
作者:
Blake Anderson;A. Chi;Scott Dunlop;D. McGrew
通讯作者:
Blake Anderson;A. Chi;Scott Dunlop;D. McGrew