HALNet - A Hybrid Deep Learning Model for Encrypted C&C Malware Traffic Detection.

Ruiyuan Li,Zehui Song,Wei Xie,Chengwei Zhang,Guohui Zhong,Xiaobing Pei
DOI: https://doi.org/10.1007/978-3-030-92708-0_21
2021-01-01
Abstract:Command and Control (C&C) malwares are particularly difficult to be detected with traditional technologies due to their explorations of multi-stage attack and encryption technology. Though Artificial Intelligence (AI) methods have shown great potential in malicious attack detection, it is difficult for C&C malwares to collect network traffic covering whole attack commands. The AI model trained with partial attack traffic needs excellent generalizability to detect the uncovered traffic. Our paper firstly analyzes the attacking progress of C&C malwares and finds a suitable way to learn the representation of C&C malicious traffic. Then we propose a hybrid Deep Learning (DL) model named HALNet with better generalizability. HALNet adopts the multi-head attention mechanism and a skip-LSTM structure to learn the two-level representation of byte feature and multi-temporal feature. Experiments show that HALNet can achieve good performance as the previous works on the public traffic dataset CICIDS2017. To better evaluate the generalizability of different models, we collect the real traffic generated by C&C malwares and construct a new malicious traffic dataset named CCE2021. With further experiments on CCE2021, HALNet can result the highest 97.95% detection accuracy on CCE-II among all the models. The overall results prove that, under approximate detection performance, HALNet has the better generalizability than the other models.
What problem does this paper attempt to address?