Encryption technology has become ubiquitous in network communication and encrypted malicious traffic detection becomes an important part of malware detection and cyber attack detection. Existing machine learning models and deep learning models are mainly trained based on packet length sequence information and time series information. Recent studies have shown that these models perform poorly in real network environments. In response to this challenge, this paper proposes a novel malicious traffic detection method based on certificate information extracted during the TLS (Transport Layer Security) encrypted handshake protocol. Our approach demonstrates that certificate information exhibits a strong correlation with the maliciousness of traffic, while remaining unaffected by the complexities of the real network environment. The experimental results illustrate that our method has high accuracy and low time overheading.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Certificate-Based Transport Layer Security Encrypted Malicious Traffic Detection in Real-Time Network Environments

  • Yiran Suo,
  • Jingfeng Xue,
  • Wenjie Guo,
  • Wenbiao Du,
  • Weijie Han,
  • Chang Xu

摘要

Encryption technology has become ubiquitous in network communication and encrypted malicious traffic detection becomes an important part of malware detection and cyber attack detection. Existing machine learning models and deep learning models are mainly trained based on packet length sequence information and time series information. Recent studies have shown that these models perform poorly in real network environments. In response to this challenge, this paper proposes a novel malicious traffic detection method based on certificate information extracted during the TLS (Transport Layer Security) encrypted handshake protocol. Our approach demonstrates that certificate information exhibits a strong correlation with the maliciousness of traffic, while remaining unaffected by the complexities of the real network environment. The experimental results illustrate that our method has high accuracy and low time overheading.