arrow
Return

Anti-EMP: Encrypted Malware Packets Filtering Algorithm Leveraging Ciphertext Patterns Under Zero Knowledge Setting

delete2026-01-01
delete0
PRE
AI
J
Junggab Son *
K
Kim, Jeehyung
A
Ahn, Jemin
D
Doowon Kim
H
Homook Cho
D
Daeyoung Kim
DOI:10.1007/978-3-031-94448-2_5delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Malware often employs encryption to obfuscate its network communications, posing challenges for network-based anomaly detection techniques. Distinguishing encrypted packets from one another becomes particularly difficult, especially when operating under zero knowledge setting, such as detecting new malware. Existing approaches rely on unique features extracted from network connections to train deep learning algorithms. However, these methods fall short when dealing with new malware due to limited information. To address this challenge, we propose Anti-EMP, an algorithm designed to filter encrypted malware packets. Specifically, Anti-EMP identifies and sifts out encrypted packets originating from the same malware across multiple clients. Our approach is grounded in two practical assumptions: (a) the packets were encrypted using an unknown, identical stream cipher and encryption key and (b) a suspicious packet related to malware can be captured. We also propose a novel method for generating Anti-EMP, significantly enhancing the capability to detect encrypted malware packets without prior knowledge, i.e., zero knowledge settings. Our experiments show that Anti-EMP can be generated in approximately one second, facilitating easy iteration and easy selection of another suspicious packet if it turns out to be ineffective. Notably, our proposed scheme demonstrates high effectiveness, achieving a True-Positive Rate (TPR) of 0.998 and a False-Positive Rate (FPR) of 0.001.
Keywords:
Malware Detection
Encrypted Malware Packets
Zero Knowledge Setting
Packet Filtering
Artificial Intelligence

Journal

S
SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM 2024, PT II
IF:
0
Papers:
18
Citations:
0

Organization

H
hanyang university
Scholars:
2.8W
Papers: 2.7W
Citations: 36
U
university of nevada las vegas
Scholars:
3.9K
Papers: 3.4K
Citations: 8
N
nevada system of higher education (nshe)
Scholars:
1.4W
Papers: 1.3W
Citations: 30
K
korea electronics technology institute (keti)
Scholars:
559
Papers: 575
Citations: 1
University of Tennessee System cover
University of Tennessee System
Scholars:
2.9W
Papers: 2.6W
Citations: 115
U
university of tennessee knoxville
Scholars:
549
Papers: 350
Citations: 0
researcher View more organizations