CBSeq: A Channel-Level Behavior Sequence for Encrypted Malware Traffic Detection

被引:5
|
作者
Cui, Susu [1 ,2 ]
Dong, Cong [3 ]
Shen, Meng [4 ]
Liu, Yuling [1 ,2 ]
Jiang, Bo [1 ,2 ]
Lu, Zhigang [1 ,2 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing 100085, Peoples R China
[2] Univ Chinese Acad Sci, Sch Cyber Secur, Beijing 100049, Peoples R China
[3] Zhongguancun Lab, Beijing 100094, Peoples R China
[4] Beijing Inst Technol, Sch Cyberspace Sci & Technol, Beijing 100081, Peoples R China
基金
北京市自然科学基金;
关键词
Malware traffic; encrypted traffic; behavior sequence; unknown detection; transformer;
D O I
10.1109/TIFS.2023.3300521
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Machine learning and neural networks have become increasingly popular solutions for encrypted malware traffic detection. They mine and learn complex traffic patterns, enabling detection by fitting boundaries between malware traffic and benign traffic. Compared with signature-based methods, they have higher scalability and flexibility. However, affected by the frequent variants and updates of malware, current methods suffer from a high false positive rate and do not work well for unknown malware traffic detection. It remains a critical task to achieve effective malware traffic detection. In this paper, we introduce CBSeq to address the above problems. CBSeq is a method that constructs a stable traffic representation, behavior sequence, to characterize attacking intent and achieve malware traffic detection. We novelly propose the channels with similar behavior as the detection object and extract side-channel content to construct behavior sequence. Unlike benign activities, the behavior sequences of malware and its variant's traffic exhibit solid internal correlations. Moreover, we design the MSFormer, a powerful Transformer-based multi-sequence fusion classifier. It captures the internal similarity of behavior sequence, thereby distinguishing malware traffic from benign traffic. Our evaluations demonstrate that CBSeq performs effectively in various known malware traffic detection and exhibits superior performance in unknown malware traffic detection, outperforming state-of-the-art methods.
引用
收藏
页码:5011 / 5025
页数:15
相关论文
共 25 条
  • [1] MalDetect: A Structure of Encrypted Malware Traffic Detection
    Liu, Jiyuan
    Zeng, Yingzhi
    Shi, Jiangyong
    Yang, Yuexiang
    Wang, Rui
    He, Liangzhong
    CMC-COMPUTERS MATERIALS & CONTINUA, 2019, 60 (02): : 721 - 739
  • [2] Malware Detection by Analysing Encrypted Network Traffic with Neural Networks
    Prasse, Paul
    Machlica, Lukas
    Pevny, Tomas
    Havelka, Jiri
    Scheffer, Tobias
    MACHINE LEARNING AND KNOWLEDGE DISCOVERY IN DATABASES, ECML PKDD 2017, PT II, 2017, 10535 : 73 - 88
  • [3] MEMTD: Encrypted Malware Traffic Detection Using Multimodal Deep Learning
    Zhang, Xiaotian
    Lu, Jintian
    Sun, Jiakun
    Xiao, Ruizhi
    Jin, Shuyuan
    WEB ENGINEERING (ICWE 2022), 2022, 13362 : 357 - 372
  • [4] Poster Abstract: Encrypted Malware Traffic Detection Using Incremental Learning
    Lee, Insup
    Roh, Heejun
    Lee, Wonjun
    IEEE INFOCOM 2020 - IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (INFOCOM WKSHPS), 2020, : 1348 - 1349
  • [5] Encrypted Malware Traffic Detection via Graph-based Network Analysis
    Fu, Zhuoqun
    Liu, Mingxuan
    Qin, Yue
    Zhang, Jia
    Zou, Yuan
    Yin, Qilei
    Li, Qi
    Duan, Haixin
    PROCEEDINGS OF 25TH INTERNATIONAL SYMPOSIUM ON RESEARCH IN ATTACKS, INTRUSIONS AND DEFENSES, RAID 2022, 2022, : 495 - 509
  • [6] MVDet: Encrypted malware traffic detection via multi-view analysis
    Cui, Susu
    Han, Xueying
    Dong, Cong
    Li, Yun
    Liu, Song
    Lu, Zhigang
    Liu, Yuling
    Journal of Computer Security, 2024, 32 (06) : 533 - 555
  • [7] Efficient Neural Architecture Transformation Search in Channel-Level for Object Detection
    Peng, Junran
    Sun, Ming
    Zhang, Zhaoxiang
    Tan, Tieniu
    Yan, Junjie
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 32 (NIPS 2019), 2019, 32
  • [8] ANDROID MALWARE CLASSIFICATION APPROACH BASED ON HOST-LEVEL ENCRYPTED TRAFFIC SHAPING
    Zhou, Jie
    Niu, Weina
    Zhang, Xiaosong
    Peng, Yujie
    Wu, Hao
    Hu, Teng
    2020 17TH INTERNATIONAL COMPUTER CONFERENCE ON WAVELET ACTIVE MEDIA TECHNOLOGY AND INFORMATION PROCESSING (ICCWAMTIP), 2020, : 246 - 249
  • [9] HALNet: A Hybrid Deep Learning Model for Encrypted C&C Malware Traffic Detection
    Li, Ruiyuan
    Song, Zehui
    Xie, Wei
    Zhang, Chengwei
    Zhong, Guohui
    Pei, Xiaobing
    NETWORK AND SYSTEM SECURITY, NSS 2021, 2021, 13041 : 326 - 339
  • [10] AS-DMF: A Lightweight Malware Encrypted Traffic Detection Method Based on Active Learning and Feature Selection
    Huo, Yuehua
    Zhao, Faqi
    Zhang, Hangsheng
    Zhuang, Shangyuan
    Sun, Jiyan
    WIRELESS COMMUNICATIONS & MOBILE COMPUTING, 2022, 2022