Abnormal Behavior Detection to Identify Infected Systems Using the APChain Algorithm and Behavioral Profiling

المؤلفون المشاركون

Lee, Sangjin
Seo, Jungwoo

المصدر

Security and Communication Networks

العدد

المجلد 2018، العدد 2018 (31 ديسمبر/كانون الأول 2018)، ص ص. 1-24، 24ص.

الناشر

Hindawi Publishing Corporation

تاريخ النشر

2018-09-04

دولة النشر

مصر

عدد الصفحات

24

التخصصات الرئيسية

تكنولوجيا المعلومات وعلم الحاسوب

الملخص EN

Recent cyber-attacks have used unknown malicious code or advanced attack techniques, such as zero-day attacks, making them extremely difficult to detect using traditional intrusion detection systems.

Botnet attacks, for example, are a very sophisticated type of cyber-security threat.

Malicious code or vulnerabilities are used to infect endpoints.

Systems infected with this malicious code connect a communications channel to a command and control (C&C) server and receive commands to perform attacks on target servers.

To effectively protect a corporate network’s resources against such threats, we must be able to detect infected systems before an attack occurs.

In this paper, an attack pattern chain algorithm (APChain) is proposed to identify infected systems in real-time network environments, and a methodology for detecting abnormal behavior through network-based behavioral profiling is explained.

APChain analyzes the attribute information of real-time network traffic, connects chains over time, and conducts behavioral profiling of different attack types to detect abnormal behavior.

The dataset used in the experiment employed real-time traffic accumulated over a period of six months, and the proposed algorithm was developed into a prototype for the experiment.

The C&C channel detection accuracy was measured at 0.996, the true positive rate at 1.0, and the false positive rate at 0.003.

This study proposes a methodology that can overcome the limitations of conventional security mechanisms and suggests an approach to the detection of abnormal behavior in a real-time network environment.

نمط استشهاد جمعية علماء النفس الأمريكية (APA)

Seo, Jungwoo& Lee, Sangjin. 2018. Abnormal Behavior Detection to Identify Infected Systems Using the APChain Algorithm and Behavioral Profiling. Security and Communication Networks،Vol. 2018, no. 2018, pp.1-24.
https://search.emarefa.net/detail/BIM-1214569

نمط استشهاد الجمعية الأمريكية للغات الحديثة (MLA)

Seo, Jungwoo& Lee, Sangjin. Abnormal Behavior Detection to Identify Infected Systems Using the APChain Algorithm and Behavioral Profiling. Security and Communication Networks No. 2018 (2018), pp.1-24.
https://search.emarefa.net/detail/BIM-1214569

نمط استشهاد الجمعية الطبية الأمريكية (AMA)

Seo, Jungwoo& Lee, Sangjin. Abnormal Behavior Detection to Identify Infected Systems Using the APChain Algorithm and Behavioral Profiling. Security and Communication Networks. 2018. Vol. 2018, no. 2018, pp.1-24.
https://search.emarefa.net/detail/BIM-1214569

نوع البيانات

مقالات

لغة النص

الإنجليزية

الملاحظات

Includes bibliographical references

رقم السجل

BIM-1214569