A Study on Time-Resilient Features for Detecting TLS Encrypted Malware Traffic
摘要
With TLS encryption becoming commonplace in today’s Internet, attackers can easily conceal their malicious activities; that is, they can easily hide malware’s Command and Control (C2) communication or Remote Access Trojan (RAT) traffic. While conventional works using machine learning attempt to detect malicious TLS-encrypted traffic mainly based on flow statistics and features of TLS metadata, they present a limitation in time resiliency. Thus, they lack robustness against time changes in both malicious and benign traffic, resulting in not long-lasting high accuracy in detection. This paper explores new time-resilient features that sustain high accuracy in the detection of TLS-encrypted malware traffic. Our proposed features utilize domain and URL reputation services as references and employ the internal structure of TLS certificates to extract characteristics of encrypted malware. In addition, a multi-view approach is introduced to extract features on sequence of packet lengths and time (SPLT). The evaluation of proposed time-resilient features is carried out using the five-year-long malware datasets. The experimental results reveal that these features are robust against the time evolution of malware activities at least for five years.