Advanced Persistent Threat (APT) is a serious threat against sensitive information. Current detection approaches are time-consuming since they detect APT attack by in-depth analysis of massive amounts of data after data breaches. Specifically, APT attackers make use of DNS to locate their command and control (C&C) servers and victims’ machines. In this paper, we propose an efficient approach to detect APT malware C&C domain with high accuracy by analyzing DNS logs. We first extract 15 features from DNS logs of mobile devices. According to Alexa ranking and the VirusTotal’s judgement result, we give each domain a score. Then, we select the most normal domains by the score metric. Finally, we utilize our anomaly detection algorithm, called Global Abnormal Forest (GAF), to identify malware C&C domains. We conduct a performance analysis to demonstrate that our approach is more efficient than other existing works in terms of calculation efficiency and recognition accuracy. Compared with Local Outlier Factor (LOF), -Nearest Neighbor (KNN), and Isolation Forest (iForest), our approach obtains more than 99% and for the detection of C&C domains. Our approach not only can reduce data volume that needs to be recorded and analyzed but also can be applicable to unsupervised learning.
from #AlexandrosSfakianakis via Alexandros G.Sfakianakis on Inoreader http://ift.tt/2nGmtC2
via IFTTT
Εγγραφή σε:
Σχόλια ανάρτησης (Atom)
Δημοφιλείς αναρτήσεις
-
Introduction Crisis management is a critical organizational function. Failure can result in serious harm to stakeholders, losses for an orga...
-
from #AlexandrosSfakianakis via Alexandros G.Sfakianakis on Inoreader http://ift.tt/2o7K1Dm via IFTTT
-
You know the feeling: you're hanging out somewhere, you look across the room, and suddenly your stomach drops. You start to sweat. Your ...
-
Maritime Logistics • General Ship Knowledge • Seaborne Cargoes and Dangerous Goods • Cargo Planning • Marine Terminal Operations • Modal and...
-
Before you begin to write a comparison essay, you should go through a a few simple steps. 50 Compare and Contrast Topics. Search the site GO...
-
AP ® United States Government and Politics 2014 Free-Response Questions © 2014 The College Board. College Board, Advanced Placement Program,...
-
Free fundraising ideas for raising money for your charity, cause or school by shopping online with your favourite retailers such as Amazon ...
-
Unit 5: Writing cohesively - Section index. This unit looks at the use of language strategies to create clear, cohesive writing. It shows yo...
-
918 quotes have been tagged as self-confidence: Edgar Allan Poe: ‘I have great faith in fools - self-confidence my friends will call it.’, R...
Δεν υπάρχουν σχόλια:
Δημοσίευση σχολίου