Application layer attacks pose an ever serious threat to network security for years since it always comes after a technically legitimate connection has been established. In recent years, cyber criminals turn to fully exploit web as a medium of communication environment to lurk a variety of forbidden or illicit activities through spreading malicious automated software(auto-ware) such as adware, spyware or bot. When these malicious auto-ware infect into a user network, they will act like robot and mimic normal behaviour web access to bypass network firewall or IDS. Besides that, in a private and large network, with huge HTTP traffic generated each day, communication behaviour identification and also classification of auto-ware is really a great challenge. In this paper, based on the previous study and analysis of the auto-ware communication behaviour and addition new features, a method classification of HTTP autoware communication is proposed. In that, a NoSql database is applied to handle with large volume unstructured HTTP requests captured every day. The method is experimented with real HTTP traffic data collected through a proxy server of a private network, from which good results are archived in classification and detection of suspicious auto-ware web access.
[1]
Yi-Shin Chen,et al.
Detect phishing by checking content consistency
,
2014,
Proceedings of the 2014 IEEE 15th International Conference on Information Reuse and Integration (IEEE IRI 2014).
[2]
N. M. Tahir,et al.
An efficient false alarm reduction approach in HTTP-based botnet detection
,
2013,
2013 IEEE Symposium on Computers & Informatics (ISCI).
[3]
Ali A. Ghorbani,et al.
Automatic discovery of botnet communities on large-scale communication networks
,
2009,
ASIACCS '09.
[4]
Anil K. Jain,et al.
A modified Hausdorff distance for object matching
,
1994,
Proceedings of 12th International Conference on Pattern Recognition.
[5]
John Heidemann,et al.
Low-rate, flow-level periodicity detection
,
2011,
2011 IEEE Conference on Computer Communications Workshops (INFOCOM WKSHPS).