DocumentCode :
1618464
Title :
Detecting Malware Outbreaks Using a Statistical Model of Blackhole Traffic
Author :
Soltani, Sohraab ; Khayam, Syed Ali ; Radha, Hayder
Author_Institution :
Dept. of Comput. Sci. & Eng., Michigan State Univ., East Lansing, MI
fYear :
2008
Firstpage :
1593
Lastpage :
1597
Abstract :
Internet blackholes have emerged as very effective tools for monitoring changes in the Internet´s traffic behavior. Prior studies have shown that traffic observed at a blackhole contains valuable information about emerging malware. While blackhole traffic has been effectively used for attack forensics, a systematic method of leveraging this traffic for online Internet- scale anomaly detection is not available. In this paper, we propose a novel technique to detect malware outbreaks using deviations in a robust statistical model of a blackhole´s traffic. First, we introduce a novel and accurate Piecewise Poisson process Model (PPM) of traffic observed at an Internet Motion Sensor (IMS) blackhole which provides a statistical quantification of the intensity or rate of incoming traffic at a blackhole, which can in turn be used to detect malware outbreaks. After establishing the accuracy of the proposed PPM model, we develop a regression model that can characterize variations in the PPM´s traffic rates. Once an accurate model of traffic rates is in place, malware outbreaks can be detected using deviations from the model´s likely statistical patterns. After removing simple deterministic patterns, we observe that a blackhole´s traffic rate residuals have a skewed and heavy-tailed behavior. Consequently, we employ a stable distribution that models variations in traffic rate residuals with very high accuracy. Finally, we propose an online detection mechanism that utilizes deviations from the rate residual distribution of blackhole traffic data to detect malware outbreaks. Experimental results using the IMS data for approximately one year show that the proposed mechanism accurately detects malware outbreaks in a timely manner.
Keywords :
Internet; computer network management; invasive software; monitoring; regression analysis; stochastic processes; telecommunication security; telecommunication traffic; Internet motion sensor; Internet traffic behavior monitoring; PPM traffic rates; attack forensics; blackhole traffic statistical model; malware outbreak detection; online Internet-scale anomaly detection; piecewise Poisson process model; regression model; Communications Society; Computer science; Computer worms; Forensics; Information technology; Internet; Robustness; Stochastic processes; Traffic control; USA Councils;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Communications, 2008. ICC '08. IEEE International Conference on
Conference_Location :
Beijing
Print_ISBN :
978-1-4244-2075-9
Electronic_ISBN :
978-1-4244-2075-9
Type :
conf
DOI :
10.1109/ICC.2008.308
Filename :
4533344
Link To Document :
بازگشت