ME-Box: A reliable method to detect malicious encrypted traffic

ME-Box: A reliable method to detect malicious encrypted traffic
复制标题

ME-Box:检测恶意加密流量的可靠方法

DOI:
10.1016/j.jisa.2021.102823
复制
发表时间:
2021
影响因子:
5.6
通讯作者:
Zhu Haiting
Zhu Haiting
中科院分区:
计算机科学3区
文献类型:
--
作者:
Xu Bingfeng;He gaofeng;Zhu Haiting

文献摘要

参考文献

相似文献

目前,越来越多的网络应用程序使用加密(如传输层安全协议)来保护其安全性和隐私,同时它也有利于网络攻击者加密其流量以逃避检测。恶意加密流量的检测正在成为网络安全的关键任务。为了完成这项任务,研究人员提出了几种启发性的方法,包括解密后进行深度数据包检测(DPI),直接对密文进行DPI以及通过机器学习算法进行识别。然而,由于隐私侵犯或性能限制,目前的最先进的是远远不能令人满意的。在本文中,我们提出了一个新的框架和系统称为ME-Box(机器学习和证据验证)的恶意加密流量的可靠检测。ME-Box具有部署在网络中的中间盒和安装在发送主机上的代理。中间盒首先通过机器学习方法评估加密流的信任度。如果某些流被分类为可疑,则中间盒提供评估结果的证据,并从代理请求对应的会话密钥。代理验证证据,如果证据令人信服,则使用正确的会话密钥进行响应。利用会话密钥,中间盒最终解密可疑的加密流,并使用入侵签名执行传统的DPI。我们实现了ME-Box的原型系统,并使用真实的恶意软件流量对其进行了测试。实验结果表明,ME-Box不需要修改现有的密码协议,能够很好地保护用户的隐私,具有实用性。
Currently, encryption (such as the Transport Layer Security protocol) is used by increasingly more network applications to protect their security and privacy, while it also benefits network attackers who can encrypt their traffic to evade detection. The detection of malicious encrypted traffic is becoming a critical task for cyber security. To accomplish this task, researchers have proposed several enlightening methods, including decryption followed by deep packet inspection (DPI), direct DPI on ciphertext and identification by machine learning algorithms. However, due to privacy violations or performance limitations, the state-of-the-art is far from satisfactory.In this paper, we propose a novel framework and system called ME-Box (Machine learning and Evidence verification) for reliable detection of malicious encrypted traffic. ME-Box has middleboxes deployed in the network and agents installed on the sending hosts. Middleboxes first evaluate the trust degrees of encrypted flows bymachine learningmethods. If some flows are classified as suspicious, then middleboxes provideevidenceof the evaluation results and request the corresponding session-keys from the agents. The agents verify the evidence, and if it is convincing, respond with the correct session-keys. With the session-keys, middleboxes finally decrypt the suspected encrypted flows and perform conventional DPI using intrusion signatures. We implement a prototype system of ME-Box and test it with real malware traffic. The experimental results show that ME-Box requires no modification of current cryptographic protocols and keeps end-users’ privacy well, and its performance is practically deployable.
DOI: 10.1145/2996758.2996768
发表时间: 2016-10
期刊: Proceedings of the 2016 ACM Workshop on Artificial Intelligence and Security
影响因子: --
作者:
Blake Anderson;D. McGrew
通讯作者: Blake Anderson;D. McGrew
DOI: 10.1007/978-3-319-46301-8_23
发表时间: 2016-09
期刊: --
影响因子: --
作者:
T. Kovanen;G. David;T. Hämäläinen
通讯作者: T. Kovanen;G. David;T. Hämäläinen
DOI: 10.1109/pimrc.2017.8292316
发表时间: 2017-10
期刊: 2017 IEEE 28th Annual International Symposium on Personal, Indoor, and Mobile Radio Communications (PIMRC)
影响因子: --
作者:
Yun-Chun Chen;Yu-Jhe Li;Aragorn Tseng;Tsungnan Lin
通讯作者: Yun-Chun Chen;Yu-Jhe Li;Aragorn Tseng;Tsungnan Lin
DOI: 10.1016/j.comnet.2019.106944
发表时间: 2019-12-24
期刊: COMPUTER NETWORKS
影响因子: 5.6
作者:
Aceto, Giuseppe;Ciuonzo, Domenico;Pescape, Antonio
通讯作者: Pescape, Antonio
DOI: 10.1145/3292006.3300025
发表时间: 2018-05
期刊: Proceedings of the Ninth ACM Conference on Data and Application Security and Privacy
影响因子: --
作者:
Blake Anderson;A. Chi;Scott Dunlop;D. McGrew
通讯作者: Blake Anderson;A. Chi;Scott Dunlop;D. McGrew