With encryption protocols widely adopted in network communication, traditional deep packet inspection methods frequently fail to detect malware traffic. Recent statistical approaches address this issue by classifying malware traffic based on features extracted from observable data fields. However, these approaches ignore potential redundancies in the features. Addressing this issue, we propose a multi-view classification approach to detect TLS encrypted malware traffic. It first extracts 21 features separated into three semantic sets/views (packet feature, TLS feature or certificate feature). Then a multi-view neural network integrates the complementary information from the three views. Nevertheless, we conduct extensive experiments demonstrating the method’s efficacy.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Encrypted Malware Traffic Detection via Multi-view Learning

  • Jitao Liu,
  • Jia He,
  • Jiyuan Liu,
  • Jiangyong Shi,
  • Yu Chen,
  • Yuexiang Yang

摘要

With encryption protocols widely adopted in network communication, traditional deep packet inspection methods frequently fail to detect malware traffic. Recent statistical approaches address this issue by classifying malware traffic based on features extracted from observable data fields. However, these approaches ignore potential redundancies in the features. Addressing this issue, we propose a multi-view classification approach to detect TLS encrypted malware traffic. It first extracts 21 features separated into three semantic sets/views (packet feature, TLS feature or certificate feature). Then a multi-view neural network integrates the complementary information from the three views. Nevertheless, we conduct extensive experiments demonstrating the method’s efficacy.