• DocumentCode
    3271213
  • Title

    Detecting hiding malicious website using network traffic mining approach

  • Author

    Hsiao, Han-Wei ; Chen, Deng-Neng ; Wu, Tsung Ju

  • Author_Institution
    Dept. of Inf. Manage., Nat. Univ. of Kaohsiung, Kaohsiung, Taiwan
  • Volume
    5
  • fYear
    2010
  • fDate
    22-24 June 2010
  • Abstract
    As the Internet continues to broaden its coverage worldwide, it has leaded to a spread of data searching, learning, entertaining, information exchanging, financing, commercial activities and so on via Internet. This tendency makes a serious situation that is the users of the Internet become attacking targets. There are many kind of network attack such as viruses, worms, and many other malicious codes were implemented to get the illegal benefits or for some particular purpose. In recent years, firewall techniques were being used to reject the anomaly Internet connections. And this has made the spreading of malwares gradually shifted from the traditional “Push-based” method to the “Pull-based” method. Therefore, how to prevent the illegitimate access from the attacker and maintaining the quality of service of network becomes an important issue of the network manager. In 2008, there was a new kind malware be found, that have some new features in comparison of the traditional malwares. Further, those codes can be self-updated by Internet. There are many malicious websites propose new version malicious code for the malware infect other computers under the same LAN to download and execute the malicious program automatically. These kinds of malicious websites cannot be easily detected in traditional firewall defense systems. This research proposed a malicious website detection system architecture and use spatial-temporal aggregating variables method to build a detection module from the NetFlow data. In our empirical evaluation results show this module has good performance to detect the malicious web sites. The results are helpful to improve the management of the large range network environment.
  • Keywords
    Internet; Web sites; authorisation; NetFlow data; anomaly Internet connection; data searching; firewall defense system; firewall technique; hiding malicious Web site; information exchanging; malicious Web site detection module; malicious Web site detection system architecture; malicious code; malicious program; malware; network attack; network traffic mining; pull-based method; push-based method; quality of service; spatial-temporal aggregating variables method; Computer architecture; Computer network management; Computer worms; Environmental management; Internet; Local area networks; Quality management; Quality of service; Telecommunication traffic; Viruses (medical); Malicious Website Detection; Malware; NetFlow; Network Security; Spatial-Temporal Pattern;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Education Technology and Computer (ICETC), 2010 2nd International Conference on
  • Conference_Location
    Shanghai
  • Print_ISBN
    978-1-4244-6367-1
  • Type

    conf

  • DOI
    10.1109/ICETC.2010.5530064
  • Filename
    5530064