Counterfeit Fingerprint Detection of Outbound HTTP Traffic with Graph Edit Distance

Chi-Kuan Chiu,Hsiao-Hsien Chang,Ching-Hao Mao,Te-En Wei
DOI: https://doi.org/10.1109/desec.2018.8625111
2018-12-01
Abstract:Malware and backdoor usually hide their malicious activities to communicate with C&C server through HTTP protocol. Various techniques for stealth are developed which directly leads security system's failure to detect hacker's activities. This paper focuses on profiling fingerprints of browsers running on different client-side host to detect anomaly among outbound HTTP traffics at behavioral and semantic level. Patterns describing fake header are also elaborately designed using graph structure and become significant features in the proposed method for the subsequent detection. Performance of proposed approach are evaluated with data from realistic environment and compare to state-of-the-art. Results show that the proposed method delivers accuracy up to 99%, also for the counterfeit fingerprint's detection it even achieve 100% recall, while the alternative approach totally failed under this scenario.
What problem does this paper attempt to address?