MVDet: Encrypted malware traffic detection via multi-view analysis

计算机科学 恶意软件 加密 计算机安全 流量分析
作者
Susu Cui,Xueying Han,Cong Dong,Yun Li,Song Liu,Zhigang Lü,Yuling Liu
出处
期刊:Journal of Computer Security [IOS Press]
卷期号:: 1-23
标识
DOI:10.3233/jcs-230024
摘要

Detecting encrypted malware traffic promptly to halt the further propagation of an attack is critical. Currently, machine learning becomes a key technique for extracting encrypted malware traffic patterns. However, due to the dynamic nature of network environments and the frequent updates of malware, current methods face the challenges of detecting unknown malware traffic in open-world environment. To address the issue, we introduce MVDet, a novel method that employs machine learning to mine the behavioral features of malware traffic based on multi-view analysis. Unlike traditional methods, MVDet innovatively characterizes the behavioral features of malware traffic at 4-tuple flows from four views: statistical view, DNS view, TLS view, and business view, which is a more stable feature representation capable of handling complex network environments and malware updates. Additionally, we achieve a short-time behavioral features construction, significantly reducing the time cost for feature extraction and malware detection. As a result, we can detect malware behavior at an early stage promptly. Our evaluation demonstrates that MVDet can detect a wide variety of known malware traffic and exhibits efficient and robust detection in both open-world and unknown malware scenarios. MVDet outperforms state-of-the-art methods in closed-world known malware detection, open-world known malware detection, and open-world unknown malware detection.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
bkagyin应助科研通管家采纳,获得10
刚刚
Hello应助科研通管家采纳,获得10
刚刚
彭于晏应助科研通管家采纳,获得10
1秒前
若ruofeng应助科研通管家采纳,获得10
1秒前
所所应助科研通管家采纳,获得10
1秒前
科研通AI5应助科研通管家采纳,获得20
1秒前
1秒前
1秒前
袖口下完成签到,获得积分10
1秒前
1秒前
mtf发布了新的文献求助10
2秒前
坚定的泥猴桃完成签到 ,获得积分10
2秒前
俊秀的海云完成签到,获得积分20
3秒前
可爱山彤完成签到,获得积分10
3秒前
yc发布了新的文献求助10
3秒前
东黎完成签到 ,获得积分10
3秒前
爆米花应助mumu采纳,获得10
4秒前
5秒前
调皮小土豆完成签到,获得积分10
5秒前
5秒前
壮观的思远应助gift采纳,获得10
6秒前
7秒前
8秒前
昏睡的蟠桃应助hdd采纳,获得30
9秒前
木偶发布了新的文献求助10
9秒前
Akim应助空域采纳,获得10
9秒前
mljever完成签到,获得积分10
9秒前
bkagyin应助北海未暖采纳,获得10
10秒前
mtf完成签到,获得积分10
10秒前
hahaha完成签到,获得积分10
10秒前
10秒前
星辰大海应助起风采纳,获得10
10秒前
kingwill应助激昂的背包采纳,获得20
11秒前
11秒前
烟花应助令狐姝采纳,获得10
12秒前
老猫322完成签到,获得积分10
13秒前
轩羊羊发布了新的文献求助10
13秒前
13秒前
小巫见大巫完成签到,获得积分20
14秒前
snowy发布了新的文献求助10
14秒前
高分求助中
All the Birds of the World 4000
Production Logging: Theoretical and Interpretive Elements 3000
Les Mantodea de Guyane Insecta, Polyneoptera 2000
Machine Learning Methods in Geoscience 1000
Resilience of a Nation: A History of the Military in Rwanda 888
Musculoskeletal Pain - Market Insight, Epidemiology And Market Forecast - 2034 666
Crystal Nonlinear Optics: with SNLO examples (Second Edition) 500
热门求助领域 (近24小时)
化学 材料科学 医学 生物 工程类 有机化学 物理 生物化学 纳米技术 计算机科学 化学工程 内科学 复合材料 物理化学 电极 遗传学 量子力学 基因 冶金 催化作用
热门帖子
关注 科研通微信公众号,转发送积分 3734857
求助须知:如何正确求助?哪些是违规求助? 3278790
关于积分的说明 10011741
捐赠科研通 2995468
什么是DOI,文献DOI怎么找? 1643460
邀请新用户注册赠送积分活动 781216
科研通“疑难数据库(出版商)”最低求助积分说明 749300