Title :
BotProfiler: Profiling Variability of Substrings in HTTP Requests to Detect Malware-Infected Hosts
Author :
Daiki Chiba;Takeshi Yagi;Mitsuaki Akiyama;Kazufumi Aoki;Takeo Hariu;Shigeki Goto
Author_Institution :
NTT Secure Platform Labs., Musashino, Japan
Abstract :
Malware is constantly evolving, which makes it difficult to prevent it from infecting hosts. Many countermeasures against malware infection, such as generating network-based signatures or templates, have been investigated. Such templates are designed to introduce regular expressions to detect polymorphic attacks conducted by attackers. A potential problem with such templates, however, is that they sometimes falsely regard benign communications as malicious, resulting in false positives, due to an inherent aspect of regular expressions. Since the cost of responding to malware infection is quite high, the number of false positives should be kept to a minimum. Therefore, we propose a system to generate templates that cause fewer false positives than a conventional system. We focused on the key idea that malicious infrastructures, such as command and control, tend to be reused instead of created from scratch. The results of implementing our system and validating it using real traffic data indicate that it reduced false positives by up to two-thirds compared to the conventional system and even increased the detection rate of infected hosts.
Keywords :
"Uniform resource locators","Malware","IP networks","Protocols","Electronic mail","Command and control systems","Organizations"
Conference_Titel :
Trustcom/BigDataSE/ISPA, 2015 IEEE
DOI :
10.1109/Trustcom.2015.444