Advanced Persistent Threat (APT) is a serious threat against sensitive information. Current detection approaches are time-consuming since they detect APT attack by in-depth analysis of massive amounts of data after data breaches. Specifically, APT attackers make use of DNS to locate their command and control (C&C) servers and victims’ machines. In this paper, we propose an efficient approach to detect APT malware C&C domain with high accuracy by analyzing DNS logs. We first extract 15 features from DNS logs of mobile devices. According to Alexa ranking and the VirusTotal’s judgement result, we give each domain a score. Then, we select the most normal domains by the score metric. Finally, we utilize our anomaly detection algorithm, called Global Abnormal Forest (GAF), to identify malware C&C domains. We conduct a performance analysis to demonstrate that our approach is more efficient than other existing works in terms of calculation efficiency and recognition accuracy. Compared with Local Outlier Factor (LOF), -Nearest Neighbor (KNN), and Isolation Forest (iForest), our approach obtains more than 99% and for the detection of C&C domains. Our approach not only can reduce data volume that needs to be recorded and analyzed but also can be applicable to unsupervised learning.
from #AlexandrosSfakianakis via Alexandros G.Sfakianakis on Inoreader http://ift.tt/2nGmtC2
via IFTTT
Εγγραφή σε:
Σχόλια ανάρτησης (Atom)
Δημοφιλείς αναρτήσεις
-
. The copytext for the following essays is the 1777 edition of the Essays and Treatises on Several Subjects. The essays themselves all appea...
-
The population of American Indians and Alaska Natives (AIAN) in the USA, which comprise about 5 million individuals, have worse health outco...
-
<span class="paragraphSection"><div class="boxTitle">Abstract</div>Despite many advances in the study ...
-
Abstract Purpose C-reactive protein and procalcitonin are reliable early predictors of infection after colorectal surgery. However, the ...
-
Strangers on the Mountain They had lived in the woodlands, twenty-five miles from New York City, for generations. Why were people so afraid ...
-
Famous Quotes: Hand Picked Funny, Inspirational and Love Quotes. Looking for the best famous quotes? from #AlexandrosSfakianakis via Alexa...
-
For the foreign language learner there exist two important criteria of any didactic edition of comprehensive literary texts. These are, on t...
-
Sample essay. The remainder of this essay writing tutorial is based on a short sample 'divorce essay' (about 1,000 words). To comple...
-
XML file created by SPI Technologies Ltd, UK in March 2002 on the basis of “The Guide to the Albert Einstein Archives, created 2002 by Ze’ev...
Δεν υπάρχουν σχόλια:
Δημοσίευση σχολίου