DocumentCode :
3777545
Title :
An Approach to Mine Suspicious Domain Based on HTTP Automated Software Communication Behavior
Author :
Tran Cong Manh;Yasuhiro Nakamura
fYear :
2015
Firstpage :
1
Lastpage :
5
Abstract :
HTTP-based automated software (auto-ware) are blooming in utilizing in reaching Internet users. Unfortunately, beside normal auto-ware such as for software updating purpose, auto-ware can be also abnormal processes acting as fraudulent advertising software, virus, spyware, and malicious bots. Malicious HTTP auto-ware will generate requests/access in communication with its server to mimic normal behavior and bypass firewall or IDS which almost allow HTTP-based data exchange. Because of that, in a private network perimeter, identifying which clients having suspicious HTTP action/auto-ware is really a big challenge. In this paper, by observing and analysis the HTTP communication behavior of malicious auto-ware, Access Variation Graph of domain/server is proposed to distinguish between normal and malicious domains/servers. Based on that, a network-based method proposal in mining suspicious domain is presented. From these results, network administrators are able to find out which clients having suspicious access/auto-ware.
Keywords :
"Servers","Feature extraction","Internet","Spyware","Security"
Publisher :
ieee
Conference_Titel :
Cyber Security, Cyber Warfare, and Digital Forensic (CyberSec), 2015 Fourth International Conference on
Type :
conf
DOI :
10.1109/CyberSec.2015.10
Filename :
7491512
Link To Document :
بازگشت