首页> 外国专利> INITIALISATION VECTOR IDENTIFICATION FOR ENCRYPTED MALWARE TRAFFIC DETECTION

INITIALISATION VECTOR IDENTIFICATION FOR ENCRYPTED MALWARE TRAFFIC DETECTION

机译:加密恶意软件流量检测的初始化矢量识别

摘要

A method for identifying malicious encrypted network traffic associated with a malware software component communicating via a network, the method including, for the malware, a portion of network traffic including a plurality of contiguous bytes occurring at a predefined offset in a network communication of the malware; extracting the defined portion of network traffic for each of a plurality of disparate encrypted network connections for the malware; training an autoencoder based on each extracted portion of network traffic, wherein the autoencoder includes: a set of input units each for representing information from a byte of an extracted portion; output units each for storing an output of the autoencoder; and a set of hidden units smaller in number than the set of input units and each interconnecting all input and all output units with weighted interconnections, such that the autoencoder is trainable to provide an approximated reconstruction of values of the input units at the output units; selecting a set of one or more offsets in the definition of a portion of network traffic as candidate locations for communication of an initialization vector for encryption of the network traffic, the selection being based on weights of interconnections in the autoencoder; and identifying malicious network traffic based on an identification of an initialization vector in the network traffic at one of the candidate locations.
机译:一种识别与经由网络通信的恶意软件软件组件相关联的恶意加密网络流量的方法,该方法包括用于恶意软件的网络流量,包括在恶意软件的网络通信中以预定义的偏移发生的多个连续字节;为恶意软件提取多个不同的加密网络连接中的每一个的网络流量的定义部分;基于网络流量的每个提取部分训练AutoEncoder,其中AutoEncoder包括:一组输入单元,每个输入单元用于表示来自提取部分的字节的信息;输出单元每个用于存储AutoEncoder的输出;并且一组隐藏单元的数量小于输入单元的组,每个输入单元互连所有输入和所有输出单元,其中AutoEncoder是可训练的,以提供输出单元处的输入单元的近似重建;选择一组一个或多个偏移,在一部分网络流量的定义中作为候选位置,用于通信用于加密网络流量的初始化向量,选择基于AutoEncoder中的互连的权重;基于在候选位置的网络流量中的识别中识别恶意网络流量。

著录项

  • 公开/公告号EP3602999B1

    专利类型

  • 公开/公告日2021-05-19

    原文格式PDF

  • 申请/专利权人

    申请/专利号EP20180713237

  • 发明设计人 EL-MOUSSA FADI;KALLOS GEORGE;

    申请日2018-03-26

  • 分类号H04L29/06;

  • 国家 EP

  • 入库时间 2022-08-24 18:44:38

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号