Real Time Detection of Malware Activities by Analyzing Darknet Traffic Using Graphical Lasso

被引:7
|
作者
Han, Chansu [1 ,2 ]
Shimamura, Jumpei [3 ]
Takahashi, Takeshi [1 ]
Inoue, Daisuke [1 ]
Kawakita, Masanori [2 ,4 ]
Takeuchi, Jun'ichi [1 ,2 ]
Nakao, Koji [1 ]
机构
[1] Natl Inst Informat & Commun Technol, Koganei, Tokyo, Japan
[2] Kyushu Univ, Fukuoka, Japan
[3] Clwit Inc, Tokyo, Japan
[4] Nagoya Univ, Nagoya, Aichi, Japan
来源
2019 18TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS/13TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING (TRUSTCOM/BIGDATASE 2019) | 2019年
关键词
Real-time detection; Malware; Network scan; Darknet; Cooperation; Outlier detection;
D O I
10.1109/TrustCom/BigDataSE.2019.00028
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recent malware evolutions have rendered cyberspace less secure, and we are currently witnessing an increasing number of severe security incidents. To minimize the impact of malware activities, it is important to detect them promptly and precisely. We have been working on this issue by monitoring traffic coming into unused IP address spaces, i.e., the darknet. On our darknet, Internet-wide scans from malware are observed as if they are coordinated or working cooperatively. Based on this observation, our earlier method monitored network traffic arriving at our darknet, estimated the degree of cooperation between each pair of the source hosts, and detected significant changes in cooperation among source hosts as a sign of newly activated malware activities. However, this method does not work in real time, and thus, it is impractical. In this study, we extend our earlier work and propose an online processing algorithm, making it possible to detect malware activities in real time. In our evaluation, we measure the detection performance of the proposed method with our proof-of-concept implementation to demonstrate its feasibility and effectiveness in terms of detecting the rise of new malware activities in real time.
引用
收藏
页码:144 / 151
页数:8
相关论文
共 50 条
  • [1] Real-Time Detection of Global Cyberthreat Based on Darknet by Estimating Anomalous Synchronization Using Graphical Lasso
    Han, Chansu
    Shimamura, Jumpei
    Takahashi, Takeshi
    Inoue, Daisuke
    Takeuchi, Jun'ichi
    Nakao, Koji
    IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2020, E103D (10) : 2113 - 2124
  • [2] Real time malware detection in encrypted network traffic using machine learning with time based features
    Singh, Abhay Pratap
    Singh, Mahendra
    JOURNAL OF DISCRETE MATHEMATICAL SCIENCES & CRYPTOGRAPHY, 2023, 26 (03): : 841 - 850
  • [3] Botnet Detection Using Graphical Lasso with Graph Density
    Han, Chansu
    Kono, Kento
    Tanaka, Shoma
    Kawakita, Masanori
    Takeuchi, Jun'ichi
    NEURAL INFORMATION PROCESSING, ICONIP 2016, PT I, 2016, 9947 : 537 - 545
  • [4] Detection and classification of darknet traffic using machine learning methods
    Ugurlu, Mesut
    Dogru, Ibrahim Alper
    Arslan, Recep Sinan
    JOURNAL OF THE FACULTY OF ENGINEERING AND ARCHITECTURE OF GAZI UNIVERSITY, 2023, 38 (03): : 1737 - 1746
  • [5] Automated Detection of Malware Activities Using Nonnegative Matrix Factorization
    Han, Chansu
    Takeuchi, Jun'ichi
    Takahashi, Takeshi
    Inoue, Daisuke
    2021 IEEE 20TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2021), 2021, : 548 - 556
  • [6] A Machine Learning Approach for Real Time Android Malware Detection
    Ngoc C Le
    Tien-Manh Nguyen
    Trang Truong
    Ngoc-Dam Nguyen
    Tra Ngo
    2020 RIVF INTERNATIONAL CONFERENCE ON COMPUTING & COMMUNICATION TECHNOLOGIES (RIVF 2020), 2020, : 347 - 352
  • [7] Real-time traffic incident detection using a probabilistic topic model
    Kinoshita, Akira
    Takasu, Atsuhiro
    Adachi, Jun
    INFORMATION SYSTEMS, 2015, 54 : 169 - 188
  • [8] A COMPREHENSIVE FRAMEWORK FOR REAL-TIME MALWARE DETECTION AND MONITORING IN PRODUCTION
    Baghirov, Elshan
    INTERNATIONAL JOURNAL ON INFORMATION TECHNOLOGIES AND SECURITY, 2024, 16 (04): : 85 - 94
  • [9] Learning Fast and Slow: Propedeutica for Real-Time Malware Detection
    Sun, Ruimin
    Yuan, Xiaoyong
    He, Pan
    Zhu, Qile
    Chen, Aokun
    Gregio, Andre
    Oliveira, Daniela
    Li, Xiaolin
    IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2022, 33 (06) : 2518 - 2529
  • [10] An optimised Darknet traffic detection system using modified locally connected CNN-BiLSTM network
    Shaikh, Abdullah Abdul Sattar
    Bhargavi, M. S.
    Kumar, C. Pavan
    INTERNATIONAL JOURNAL OF AD HOC AND UBIQUITOUS COMPUTING, 2023, 43 (02) : 87 - 96