DocumentCode
3271213
Title
Detecting hiding malicious website using network traffic mining approach
Author
Hsiao, Han-Wei ; Chen, Deng-Neng ; Wu, Tsung Ju
Author_Institution
Dept. of Inf. Manage., Nat. Univ. of Kaohsiung, Kaohsiung, Taiwan
Volume
5
fYear
2010
fDate
22-24 June 2010
Abstract
As the Internet continues to broaden its coverage worldwide, it has leaded to a spread of data searching, learning, entertaining, information exchanging, financing, commercial activities and so on via Internet. This tendency makes a serious situation that is the users of the Internet become attacking targets. There are many kind of network attack such as viruses, worms, and many other malicious codes were implemented to get the illegal benefits or for some particular purpose. In recent years, firewall techniques were being used to reject the anomaly Internet connections. And this has made the spreading of malwares gradually shifted from the traditional “Push-based” method to the “Pull-based” method. Therefore, how to prevent the illegitimate access from the attacker and maintaining the quality of service of network becomes an important issue of the network manager. In 2008, there was a new kind malware be found, that have some new features in comparison of the traditional malwares. Further, those codes can be self-updated by Internet. There are many malicious websites propose new version malicious code for the malware infect other computers under the same LAN to download and execute the malicious program automatically. These kinds of malicious websites cannot be easily detected in traditional firewall defense systems. This research proposed a malicious website detection system architecture and use spatial-temporal aggregating variables method to build a detection module from the NetFlow data. In our empirical evaluation results show this module has good performance to detect the malicious web sites. The results are helpful to improve the management of the large range network environment.
Keywords
Internet; Web sites; authorisation; NetFlow data; anomaly Internet connection; data searching; firewall defense system; firewall technique; hiding malicious Web site; information exchanging; malicious Web site detection module; malicious Web site detection system architecture; malicious code; malicious program; malware; network attack; network traffic mining; pull-based method; push-based method; quality of service; spatial-temporal aggregating variables method; Computer architecture; Computer network management; Computer worms; Environmental management; Internet; Local area networks; Quality management; Quality of service; Telecommunication traffic; Viruses (medical); Malicious Website Detection; Malware; NetFlow; Network Security; Spatial-Temporal Pattern;
fLanguage
English
Publisher
ieee
Conference_Titel
Education Technology and Computer (ICETC), 2010 2nd International Conference on
Conference_Location
Shanghai
Print_ISBN
978-1-4244-6367-1
Type
conf
DOI
10.1109/ICETC.2010.5530064
Filename
5530064
Link To Document