arrow
Return

A malware traffic detection method based on Victim-Attacker interaction patterns

delete2025-05-01
delete0
PRE
AI
Q
Qu, Yanze
H
Hailong Ma
Z
Zheng, Chaofan
江一鸣 cover
江一鸣 (Yiming Jiang)
W
Wenbo Wang *
DOI:10.1016/j.cose.2025.104487delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
The widespread adoption of encryption protocols has provided benefits for personal privacy, while also offering cover for the command and control (C&C) communication of malware such as Trojans, presenting significant challenges to existing network monitoring systems. Existing methods exhibit limited capacity to discern threats across network flows, while neglecting the prevalent packet loss phenomenon in real-world network environments. This paper proposes a malware traffic detection method based on the interaction patterns between compromised hosts and C&C servers. With a novel detection unit called channel unit representing interaction patterns, compared to existing methods, our proposed method is capable of discerning threats across network flows and is more resilient to packet loss. Evaluation experiments show that our method has superior detection performance in both binary and multi-class classification scenarios, achieving accuracy rates of 99.84 % and 96.08 % respectively. In terms of packet loss tolerance, compared with existing methods, our method exhibits the minimal performance degradation under a 20 % packet loss rate, maintaining a multi-classification accuracy of 99.63 % and a binary classification accuracy of 95.72 %.
Keywords:
Malware traffic
Encrypted traffic
Intrusion detection
Network security

Journal

C
Computers and Security
IF:
5.4
Papers:
4.6K
Citations:
1.4W

Organization

I
Informat Engn Univ
Scholars:
214
Papers: 73
Citations: 10