Deteksi Malware Dridex Menggunakan Signature-based Snort

  • Nugraha A
  • Gustian D
N/ACitations
Citations of this article
26Readers
Mendeley users who have this article in their library.

Abstract

Currently malware is a dangerous application and continues to grow so that it becomes a threat when using internet services. One of the most dangerous malware in 2020 is Dridex which targets and steals banking credentials and personal information regarding a person's financial records. Dridex makes use of email spam and social engineering for its distribution. It is noted that this malware has made a loss of up to $100 million. This study focuses on analyzing Dridex activity through a network traffic dataset and then developing snort rules based on the Dridex signatures that have been found. This study has developed 12 (twelve) rules that are implemented on Snort to detect the presence of Dridex signatures. Testing the success of Dridex detection was carried out using confusion matrix techniques and resulted in an accuracy value of 88.5%, a recall or decision rate of 100%, and a precision value of 84.75%.

Cite

CITATION STYLE

APA

Nugraha, A., & Gustian, D. A. (2022). Deteksi Malware Dridex Menggunakan Signature-based Snort. Indonesian Journal of Computer Science, 10(1). https://doi.org/10.33022/ijcs.v10i1.3068

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free