• DocumentCode
    3712685
  • Title

    Malware traffic detection using tamper resistant features

  • Author

    Z. Berkay Celik;Robert J. Walls;Patrick McDaniel;Ananthram Swami

  • Author_Institution
    Department of Computer Science and Engineering, The Pennsylvania State University, United States of America
  • fYear
    2015
  • Firstpage
    330
  • Lastpage
    335
  • Abstract
    This paper presents a framework for evaluating the transport layer feature space of malware heartbeat traffic. We utilize these features in a prototype detection system to distinguish malware traffic from traffic generated by legitimate applications. In contrast to previous work, we eliminate features at risk of producing overly optimistic detection results, detect previously unobserved anomalous behavior, and rely only on tamper-resistant features making it difficult for sophisticated malware to avoid detection. Further, we characterize the evolution of malware evasion techniques over time by examining the behavior of 16 malware families. In particular, we highlight the difficultly of detecting malware that use traffic-shaping techniques to mimic legitimate traffic.
  • Keywords
    "Artificial neural networks","Malware","Servers"
  • Publisher
    ieee
  • Conference_Titel
    Military Communications Conference, MILCOM 2015 - 2015 IEEE
  • Type

    conf

  • DOI
    10.1109/MILCOM.2015.7357464
  • Filename
    7357464