Classification of malware network activity

4Citations
Citations of this article
4Readers
Mendeley users who have this article in their library.
Get full text

Abstract

In the previous work, we have designed and implemented a platform with tools for capturing malware, running botnets in a controlled environment, analyzing their interactions with a botmaster, testing methods and techniques for mitigating botnet nuisance, and eventually disrupting them. We have used the platform to gather a large number of malware and observe its network activity. In this paper, we present an approach to malware classification based on the observation of the malware communication behavior. First, we show that traditional methods based on antivirus tools are not suitable for classification. Then, we define the method based on observing the communication pattern of executing malware. We report on the classification results obtained with the proposed method. Unlike classification done by existing antivirus tools, the proposed method results in selective and consistent classification. © 2012 Springer-Verlag.

Cite

CITATION STYLE

APA

Berger-Sabbatel, G., & Duda, A. (2012). Classification of malware network activity. In Communications in Computer and Information Science (Vol. 287 CCIS, pp. 24–35). https://doi.org/10.1007/978-3-642-30721-8_3

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free