用上下文摘要识别隐蔽的APT恶意通信,准确率超93%。
Detecting APT Malware Command and Control over HTTP(S) Using Contextual Summaries
- 构建流量上下文摘要PairFlow,融合行为与协议特征
- 对未见过的APT攻击实现93.02%的平均F1分数
- 适合安全团队用于检测长期潜伏的隐蔽攻击
高级持续性威胁(APTs)是全球关键组织面临的最复杂威胁之一。与频繁且激进的攻击不同,APT采用特定战术、技术和程序(TTPs),难以被现有网络入侵检测系统发现,常在受害主机上潜伏数月甚至数年。本文提出EarlyCrow,一种基于上下文摘要的HTTP(S)通道中APT恶意命令与控制通信检测方法。其设计基于针对近期APT活动中使用的工具所生成流量的新型威胁模型,强调恶意连接周围的上下文信息,并指出有助于检测的关键流量属性。EarlyCrow定义了一种名为PairFlow的多功能网络流格式,用于构建PCAP捕获的上下文摘要,表征与APT TTPs相关的关键行为、统计及协议信息。在未见过的APT样本上评估显示,EarlyCrow取得93.02%的宏观平均F1分数,误报率仅为0.74%。
原文摘要 · Abstract (English)
Advanced Persistent Threats (APTs) are among the most sophisticated threats facing critical organizations worldwide. APTs employ specific tactics, techniques, and procedures (TTPs) which make them difficult to detect in comparison to frequent and aggressive attacks. In fact, current network intrusion detection systems struggle to detect APTs communications, allowing such threats to persist unnoticed on victims' machines for months or even years. In this paper, we present EarlyCrow, an approach to detect APT malware command and control over HTTP(S) using contextual summaries. The design of EarlyCrow is informed by a novel threat model focused on TTPs present in traffic generated by tools recently used as part of APT campaigns. The threat model highlights the importance of the context around the malicious connections, and suggests traffic attributes which help APT detection. EarlyCrow defines a novel multipurpose network flow format called PairFlow, which is leveraged to build the contextual summary of a PCAP capture, representing key behavioral, statistical and protocol information relevant to APT TTPs. We evaluate the effectiveness of EarlyCrow on unseen APTs obtaining a headline macro average F1-score of 93.02% with FPR of $0.74%.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。