Advanced Persistent Threat (APT) is a serious threat against sensitive information. Current detection approaches are time-consuming since they detect APT attack by in-depth analysis of massive amounts of data after data breaches. Specifically, APT attackers make use of DNS to locate their command and control (C&C) servers and victims’ machines. In this paper, we propose an efficient approach to detect APT malware C&C domain with high accuracy by analyzing DNS logs. We first extract 15 features from DNS logs of mobile devices. According to Alexa ranking and the VirusTotal’s judgement result, we give each domain a score. Then, we select the most normal domains by the score metric. Finally, we utilize our anomaly detection algorithm, called Global Abnormal Forest (GAF), to identify malware C&C domains. We conduct a performance analysis to demonstrate that our approach is more efficient than other existing works in terms of calculation efficiency and recognition accuracy. Compared with Local Outlier Factor (LOF), -Nearest Neighbor (KNN), and Isolation Forest (iForest), our approach obtains more than 99% and for the detection of C&C domains. Our approach not only can reduce data volume that needs to be recorded and analyzed but also can be applicable to unsupervised learning.
from #AlexandrosSfakianakis via Alexandros G.Sfakianakis on Inoreader http://ift.tt/2nGmtC2
via IFTTT
Εγγραφή σε:
Σχόλια ανάρτησης (Atom)
Δημοφιλείς αναρτήσεις
-
Essay Thesaurus Generator eisenschiml thesis Short essay on great wall of china how to start a compare and contrast essay sample assessing c...
-
How to write a Scholarship Essay - Examples. Scholarship Essays should use this formatting unless specified otherwise: Two to three pages in...
-
The Notch signaling pathway is a very conserved system that controls embryonic cell fate decisions and the maintenance of adult stem cells t...
-
Through the Wormhole: Is There an Edge to... Science - 43 min - ★ It is commonly theorized that the universe began with the Big Bang... Thro...
-
http://ift.tt/2p7HgAl
-
Web version of a book about Subversion. Work in progress, however already very complete. The book should be published by O'Reilly and As...
-
Reported by Scientific American, this Week in World War I: March 24, 1917 -- Read more on ScientificAmerican.com from #Alexandro...
-
from #AlexandrosSfakianakis via Alexandros G.Sfakianakis on Inoreader http://ift.tt/2octpu9 via IFTTT
-
Publication date: March 2017 Source: Clinical Biochemistry, Volume 50, Issues 4–5 Author(s): Rosalina Martínez-López, Paloma Ropero, Crist...
Δεν υπάρχουν σχόλια:
Δημοσίευση σχολίου