Real Time Detection of Malware Activities by Analyzing Darknet Traffic Using Graphical Lasso

被引:7
|
作者
Han, Chansu [1 ,2 ]
Shimamura, Jumpei [3 ]
Takahashi, Takeshi [1 ]
Inoue, Daisuke [1 ]
Kawakita, Masanori [2 ,4 ]
Takeuchi, Jun'ichi [1 ,2 ]
Nakao, Koji [1 ]
机构
[1] Natl Inst Informat & Commun Technol, Koganei, Tokyo, Japan
[2] Kyushu Univ, Fukuoka, Japan
[3] Clwit Inc, Tokyo, Japan
[4] Nagoya Univ, Nagoya, Aichi, Japan
来源
2019 18TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS/13TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING (TRUSTCOM/BIGDATASE 2019) | 2019年
关键词
Real-time detection; Malware; Network scan; Darknet; Cooperation; Outlier detection;
D O I
10.1109/TrustCom/BigDataSE.2019.00028
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recent malware evolutions have rendered cyberspace less secure, and we are currently witnessing an increasing number of severe security incidents. To minimize the impact of malware activities, it is important to detect them promptly and precisely. We have been working on this issue by monitoring traffic coming into unused IP address spaces, i.e., the darknet. On our darknet, Internet-wide scans from malware are observed as if they are coordinated or working cooperatively. Based on this observation, our earlier method monitored network traffic arriving at our darknet, estimated the degree of cooperation between each pair of the source hosts, and detected significant changes in cooperation among source hosts as a sign of newly activated malware activities. However, this method does not work in real time, and thus, it is impractical. In this study, we extend our earlier work and propose an online processing algorithm, making it possible to detect malware activities in real time. In our evaluation, we measure the detection performance of the proposed method with our proof-of-concept implementation to demonstrate its feasibility and effectiveness in terms of detecting the rise of new malware activities in real time.
引用
收藏
页码:144 / 151
页数:8
相关论文
共 50 条
  • [41] A Real-Time PE-Malware Detection System Based on CHI-Square Test and PE-File Features
    Belaoued, Mohamed
    Mazouzi, Smaine
    COMPUTER SCIENCE AND ITS APPLICATIONS, CIIA 2015, 2015, 456 : 416 - 425
  • [42] Real-time traffic accident detection and evaluation based on Seq2Seq and autoencode model
    Zhao C.
    Xie T.
    Xin G.-R.
    Wu J.
    Kongzhi yu Juece/Control and Decision, 2022, 37 (08): : 2141 - 2148
  • [43] TTD-YOLO: A Real-Time Traffic Target Detection Algorithm Based on YOLOV5
    Xia, Wenjun
    Li, Peiqing
    Huang, Heyu
    Li, Qipeng
    Yang, Taiping
    Li, Zhuoran
    IEEE ACCESS, 2024, 12 : 66419 - 66431
  • [44] Real-Time Stroke Detection Using Deep Learning and Federated Learning
    Elhanashi, Abdussalam
    Dini, Pierpaolo
    Saponara, Sergio
    Zheng, Qinghe
    Alsharif, Ibrahim
    REAL-TIME PROCESSING OF IMAGE, DEPTH, AND VIDEO INFORMATION 2024, 2024, 13000
  • [45] Real-time Detection of Vehicle and Traffic Light for Intelligent and Connected Vehicles Based on YOLOv3 Network
    Du, Luyao
    Chen, Wei
    Fu, Shuaizhi
    Kong, Haiyang
    Li, Changzhen
    Pei, Monghui
    2019 5TH INTERNATIONAL CONFERENCE ON TRANSPORTATION INFORMATION AND SAFETY (ICTIS 2019), 2019, : 388 - 392
  • [46] Comparative Study of K-means and Mini Batch K-means Clustering Algorithms in Android Malware Detection Using Network Traffic Analysis
    Feizollah, Ali
    Anuar, Nor Badrul
    Salleh, Rosli
    Amalina, Fairuz
    2014 INTERNATIONAL SYMPOSIUM ON BIOMETRICS AND SECURITY TECHNOLOGIES (ISBAST), 2014, : 193 - 197
  • [47] FraudMove: Fraud Drivers Discovery Using Real-Time Trajectory Outlier Detection
    Eldawy, Eman O.
    Hendawi, Abdeltawab
    Abdalla, Mohammed
    Mokhtar, Hoda M. O.
    ISPRS INTERNATIONAL JOURNAL OF GEO-INFORMATION, 2021, 10 (11)
  • [48] Automatic real-time crack detection using lightweight deep learning models
    Su, Guoshao
    Qin, Yuanzhuo
    Xu, Huajie
    Liang, Jinfu
    ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2024, 138
  • [49] Real-time network intrusion detection using deferred decision and hybrid classifier
    Kim, Taehoon
    Pak, Wooguil
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2022, 132 : 51 - 66
  • [50] Real-Time Object Detection to Identify Adults and Children Using YOLO Algorithms
    Abdulghani, Abdulghani M.
    Abdulghani, Mokhles M.
    Walters, Wilbur L.
    Abed, Khalid H.
    2023 INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE AND COMPUTATIONAL INTELLIGENCE, CSCI 2023, 2023, : 1146 - 1151