The malware generates malicious network behavior, often hiding it in HTTP traffic to avoid detection. So, in cyber security, detecting malicious traffic is one of the critical issues caused by malware.
However, besides this, all the current methods primarily rely on artificial features and outdated data, lacking generalization.
The following cybersecurity researchers from their respective universities and organizations have recently unveiled how they detected malicious HTTP traffic that hides within the real traffic:-
Protect your Business Email from threats like tracking, blocking, modifying, phishing, account takeover, business email compromise, malware, and ransomware with Trustifi’s AI-powered email security solution.
HTTP traffic carries much of this behavior, with adversaries mimicking innocent user behavior and hiding negative data within standard fields.
The similarity to harmless traffic makes the detection challenging, and this scenario also drives the need for advanced techniques.
It is crucial to enhance detection methods’ ability to generalize and identify unknown HTTP-based malicious communication behavior, but it faces two main challenges.
Below, we have mentioned the two challenges:-
Challenges in detecting unknown HTTP-based malicious behavior include the difficulty of feature extraction under adversarial conditions and limited testing on small-scale datasets, which hampers generalization ability.
Below, we have mentioned the four phases into which an HTTP-based malware attack can be divided:-
Effective detection of HTTP-based malicious behavior occurs in the communication phase by analyzing malware-generated traffic to identify malicious interactions and locate adversaries.
Full-duplex application layer flows involve request and response packets with the same quintuple:-
Besides this, the cybersecurity researchers divide flows into packet-level and flow-level to extract hierarchical features.
The HMCD model demonstrates excellent detection performance with F1 at 99.46% in the HMCT-2020 dataset. It also outperforms other models in generalization and real-world traffic experiments, achieving an F1 of 83.66%.
Experts propose the HMCD-Model for detecting unknown malicious HTTP traffic, using a hybrid neural network with GAN to enhance accurate traffic representation, achieving F1 ≈ 83.66%.
HMCD improves defense against complex attacks, with plans to expand datasets and refine GAN-based traffic generation.
Keep informed about the latest Cyber Security News by following us on Google News, Linkedin, Twitter, and Facebook.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…