Causality reasoning about network events for detecting stealthy malware activities. Issue 58 (May 2016)
- Record Type:
- Journal Article
- Title:
- Causality reasoning about network events for detecting stealthy malware activities. Issue 58 (May 2016)
- Main Title:
- Causality reasoning about network events for detecting stealthy malware activities
- Authors:
- Zhang, Hao
Yao, Danfeng (Daphne)
Ramakrishnan, Naren
Zhang, Zhibin - Abstract:
- Abstract: Malicious software activities have become more and more clandestine, making them challenging to detect. Existing security solutions rely heavily on the recognition of known code or behavior signatures, which are incapable of detecting new malware patterns. We propose to discover the triggering relations on network requests and leverage the structural information to identify stealthy malware activities that cannot be attributed to a legitimate cause. The triggering relation is defined as the temporal and causal relationship between two events. We design and compare rule- and learning-based methods to infer the triggering relations on network data. We further introduce a user-intention based security policy for pinpointing stealthy malware activities based on a triggering relation graph. We extensively evaluate our solution on a DARPA dataset and 7 GB real-world network traffic. Results indicate that our dependence analysis successfully detects various malware activities including spyware, data exfiltrating malware, and DNS bots on hosts. With good scalability for large datasets, the learning-based method achieves better classification accuracy than the rule-based one. The significance of our traffic reasoning approach is its ability to detect new and stealthy malware activities.
- Is Part Of:
- Computers & security. Issue 58(2016)
- Journal:
- Computers & security
- Issue:
- Issue 58(2016)
- Issue Display:
- Volume 58, Issue 58 (2016)
- Year:
- 2016
- Volume:
- 58
- Issue:
- 58
- Issue Sort Value:
- 2016-0058-0058-0000
- Page Start:
- 180
- Page End:
- 198
- Publication Date:
- 2016-05
- Subjects:
- Network security -- Anomaly detection -- Stealthy malware -- Traffic analysis -- Dependence analysis -- Machine learning classification
Computer security -- Periodicals
Electronic data processing departments -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.sciencedirect.com/science/journal/01674048 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.cose.2016.01.002 ↗
- Languages:
- English
- ISSNs:
- 0167-4048
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3394.781000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 1803.xml