With TLS encryption becoming commonplace in today’s Internet, attackers can easily conceal their malicious activities; that is, they can easily hide malware’s Command and Control (C2) communication or Remote Access Trojan (RAT) traffic. While conventional works using machine learning attempt to detect malicious TLS-encrypted traffic mainly based on flow statistics and features of TLS metadata, they present a limitation in time resiliency. Thus, they lack robustness against time changes in both malicious and benign traffic, resulting in not long-lasting high accuracy in detection. This paper explores new time-resilient features that sustain high accuracy in the detection of TLS-encrypted malware traffic. Our proposed features utilize domain and URL reputation services as references and employ the internal structure of TLS certificates to extract characteristics of encrypted malware. In addition, a multi-view approach is introduced to extract features on sequence of packet lengths and time (SPLT). The evaluation of proposed time-resilient features is carried out using the five-year-long malware datasets. The experimental results reveal that these features are robust against the time evolution of malware activities at least for five years.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Study on Time-Resilient Features for Detecting TLS Encrypted Malware Traffic

  • Kaisei Fujiwara,
  • Akira Yamada,
  • Seiichi Ozawa,
  • Chanho Park

摘要

With TLS encryption becoming commonplace in today’s Internet, attackers can easily conceal their malicious activities; that is, they can easily hide malware’s Command and Control (C2) communication or Remote Access Trojan (RAT) traffic. While conventional works using machine learning attempt to detect malicious TLS-encrypted traffic mainly based on flow statistics and features of TLS metadata, they present a limitation in time resiliency. Thus, they lack robustness against time changes in both malicious and benign traffic, resulting in not long-lasting high accuracy in detection. This paper explores new time-resilient features that sustain high accuracy in the detection of TLS-encrypted malware traffic. Our proposed features utilize domain and URL reputation services as references and employ the internal structure of TLS certificates to extract characteristics of encrypted malware. In addition, a multi-view approach is introduced to extract features on sequence of packet lengths and time (SPLT). The evaluation of proposed time-resilient features is carried out using the five-year-long malware datasets. The experimental results reveal that these features are robust against the time evolution of malware activities at least for five years.