A learning evasive email-based P2P-like botnet

A learning evasive email-based P2P-like botnet
复制标题

DOI:
10.1109/cc.2018.8300268
复制
发表时间:
2018-02
影响因子:
4.1
通讯作者:
Zhi Wang;Meilin Qin;Mengqi Chen;Chunfu Jia;Yong Ma
Zhi Wang;Meilin Qin;Mengqi Chen;Chunfu Jia;Yong Ma
中科院分区:
计算机科学3区
文献类型:
--
作者:
Zhi Wang;Meilin Qin;Mengqi Chen;Chunfu Jia;Yong Ma

文献摘要

被引文献

相似文献

目前,机器学习作为恶意软件检测系统的核心组成部分得到了广泛的应用。机器学习算法是在假设所有数据集都遵循相同的底层数据分布的情况下设计的。但现实世界中的恶意软件数据分布并不稳定,而且会随着时间的推移而变化。通过利用机器学习算法和恶意软件数据概念漂移问题的知识,我们提出了一种新的学习规避僵尸网络体系结构和一种隐蔽且安全的C&C机制。在邮件通信通道的基础上,利用邮件服务器的良好信誉和同一通道内大量的良性邮件通信,构建了一个基于P2P的隐形邮件僵尸网络。实验结果表明,基于流量特征和时间相关特征的水平相关学习算法很难有足够的置信度将恶意邮件流量与正常邮件流量区分开来。我们讨论了恶意软件数据的概念漂移和可能的防御策略。
Nowadays, machine learning is widely used in malware detection system as a core component. The machine learning algorithm is designed under the assumption that all datasets follow the same underlying data distribution. But the real-world malware data distribution is not stable and changes with time. By exploiting the knowledge of the machine learning algorithm and malware data concept drift problem, we show a novel learning evasive botnet architecture and a stealthy and secure C&C mechanism. Based on the email communication channel, we construct a stealthy email-based P2P-like botnet that exploit the excellent reputation of email servers and a huge amount of benign email communication in the same channel. The experiment results show horizontal correlation learning algorithm is difficult to separate malicious email traffic from normal email traffic based on the volume features and time-related features with enough confidence. We discuss the malware data concept drift and possible defense strategies.