Identifying malicious hosts involved in periodic communications

dc.contributor.authorApruzzese, Giovanni
dc.contributor.authorMarchetti, Mirco
dc.contributor.authorColajanni, Michele
dc.contributor.authorZoccoli, Gabriele Gambigliani
dc.contributor.authorGuido, Alessandro
dc.contributor.authorAvresky, Dimiter R.
dc.contributor.authorGkoulalas-Divanis, Aris
dc.contributor.authorAvresky, Dimiter R.
dc.contributor.authorCorreia, Miguel P.
dc.contributor.departmentDepartment of Computer Science
dc.date.accessioned2026-09-24T13:48:01Z
dc.date.available2026-09-24T13:48:01Z
dc.date.issued2017-12-08
dc.descriptionPublisher Copyright: © 2017 IEEE.en
dc.description.abstractAfter many research efforts, Network Intrusion Detection Systems still have much room for improvement. This paper proposes a novel method for automatic and timely analysis of traffic generated by large networks, which is able to identify malicious external hosts even if their activities do not raise any alert by existing defensive systems. Our proposal focuses on periodic communications, since our experimental evaluation shows that they are more related to malicious activities, and it can be easily integrated with other detection systems. We highlight that periodic network activities can occur at very different intervals ranging from seconds to hours, hence a timely analysis of long time-windows of the traffic generated by large organizations is a challenging task in itself. Existing work is primarily focused on identifying botnets, whereas the method proposed in this paper has a broader target and aims to detect external hosts that are likely involved in any malicious operation. Since malware-related network activities can be considered as rare events in the overall traffic, the output of the proposed method is a manageable graylist of external hosts that are characterized by a considerably higher likelihood of being malicious compared to the entire set of external hosts contacted by the monitored large network. A thorough evaluation on a real large network traffic demonstrates the effectiveness of our proposal, which is capable of automatically selecting only dozens of suspicious hosts from hundreds of thousands, thus allowing security operators to focus their analyses on few likely malicious targets.en
dc.description.versionPeer revieweden
dc.format.extent8
dc.format.extent1085879
dc.format.extent1-8
dc.format.extent
dc.identifier.citationApruzzese, G, Marchetti, M, Colajanni, M, Zoccoli, G G & Guido, A 2017, Identifying malicious hosts involved in periodic communications. in D R Avresky, A Gkoulalas-Divanis, D R Avresky & M P Correia (eds), 2017 IEEE 16th International Symposium on Network Computing and Applications, NCA 2017. 2017 IEEE 16th International Symposium on Network Computing and Applications, NCA 2017, vol. 2017-January, Institute of Electrical and Electronics Engineers Inc., pp. 1-8, 16th IEEE International Symposium on Network Computing and Applications, NCA 2017, Cambridge, United States, 30/10/17. https://doi.org/10.1109/NCA.2017.8171326en
dc.identifier.citationconferenceen
dc.identifier.doi10.1109/NCA.2017.8171326
dc.identifier.isbn9781538614655
dc.identifier.other250864207
dc.identifier.other99aef363-d325-4c95-a580-9b74307710b2
dc.identifier.other85046449249
dc.identifier.urihttps://hdl.handle.net/20.500.11815/8352
dc.language.isoen
dc.publisherInstitute of Electrical and Electronics Engineers Inc.
dc.relation.ispartofseries2017 IEEE 16th International Symposium on Network Computing and Applications, NCA 2017; ()en
dc.relation.ispartofseries2017 IEEE 16th International Symposium on Network Computing and Applications, NCA 2017; 2017-January()en
dc.relation.urlhttps://www.scopus.com/pages/publications/85046449249en
dc.rightsinfo:eu-repo/semantics/openAccessen
dc.subjectbeaconingen
dc.subjectclusteringen
dc.subjectgraylisten
dc.subjectperiodicityen
dc.subjectArtificial Intelligenceen
dc.subjectComputer Networks and Communicationsen
dc.subjectHardware and Architectureen
dc.titleIdentifying malicious hosts involved in periodic communicationsen
dc.type/dk/atira/pure/researchoutput/researchoutputtypes/contributiontobookanthology/conferenceen

Skrár

Original bundle

Niðurstöður 1 - 1 af 1
Nafn:
Identifying_malicious_hosts_involved_in_periodic_communications.pdf
Stærð:
1.04 MB
Snið:
Adobe Portable Document Format