CSpace  > 中国科学院计算技术研究所期刊论文  > 英文
Causality reasoning about network events for detecting stealthy malware activities
Zhang, Hao1; Yao, Danfeng (Daphne)1; Rarnakrishnan, Naren1; Zhang, Zhibin2
2016-05-01
发表期刊COMPUTERS & SECURITY
ISSN0167-4048
卷号58页码:180-198
摘要Malicious software activities have become more and more clandestine, making them challenging to detect. Existing security solutions rely heavily on the recognition of known code or behavior signatures, which are incapable of detecting new maiware patterns. We propose to discover the triggering relations on network requests and leverage the structural information to identify stealthy malware activities that cannot be attributed to a legitimate cause. The triggering relation is defined as the temporal and causal, relationship between two events. We design and compare rule- and learning-based methods to infer the triggering relations on network data. We further introduce a user-intention based security policy for pinpointing stealthy malware activities based on a triggering relation graph. We extensively evaluate our solution on a DARPA dataset and 7 GB real-world network traffic. Results indicate that our dependence analysis successfully detects various maiware activities including spyware, data exfiltrating malware, and DNS bots on hosts. With good scalability for large datasets, the learning-based method achieves better classification accuracy than the rule-based one. The significance of our traffic reasoning approach is its ability to detect new and stealthy malware activities. (C) 2016 The Authors. Published by Elsevier Ltd.
关键词Network security Anomaly detection Stealthy maiware Traffic analysis Dependence analysis Machine learning classification
DOI10.1016/j.cose.2016.01.002
收录类别SCI
语种英语
资助项目NSF[CAREER CNS-0953638] ; NSF[ARO YIP W911NF-14-1-0535] ; L-3 communications
WOS研究方向Computer Science
WOS类目Computer Science, Information Systems
WOS记录号WOS:000372764600012
出版者ELSEVIER ADVANCED TECHNOLOGY
引用统计
被引频次:32[WOS]   [WOS记录]     [WOS相关记录]
文献类型期刊论文
条目标识符http://119.78.100.204/handle/2XEOYT63/8417
专题中国科学院计算技术研究所期刊论文_英文
通讯作者Yao, Danfeng (Daphne)
作者单位1.Virginia Tech, Dept Comp Sci, Blacksburg, VA USA
2.Chinese Acad Sci, Inst Comp Technol, Beijing, Peoples R China
推荐引用方式
GB/T 7714
Zhang, Hao,Yao, Danfeng ,Rarnakrishnan, Naren,et al. Causality reasoning about network events for detecting stealthy malware activities[J]. COMPUTERS & SECURITY,2016,58:180-198.
APA Zhang, Hao,Yao, Danfeng ,Rarnakrishnan, Naren,&Zhang, Zhibin.(2016).Causality reasoning about network events for detecting stealthy malware activities.COMPUTERS & SECURITY,58,180-198.
MLA Zhang, Hao,et al."Causality reasoning about network events for detecting stealthy malware activities".COMPUTERS & SECURITY 58(2016):180-198.
条目包含的文件
条目无相关文件。
个性服务
推荐该条目
保存到收藏夹
查看访问统计
导出为Endnote文件
谷歌学术
谷歌学术中相似的文章
[Zhang, Hao]的文章
[Yao, Danfeng (Daphne)]的文章
[Rarnakrishnan, Naren]的文章
百度学术
百度学术中相似的文章
[Zhang, Hao]的文章
[Yao, Danfeng (Daphne)]的文章
[Rarnakrishnan, Naren]的文章
必应学术
必应学术中相似的文章
[Zhang, Hao]的文章
[Yao, Danfeng (Daphne)]的文章
[Rarnakrishnan, Naren]的文章
相关权益政策
暂无数据
收藏/分享
所有评论 (0)
暂无评论
 

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。