Detection of Android Malware Behavior in Browser Downloads

Min-Hao Wu, Limin Yi, Ting-Cheng Chang, Yiwan Chen, Caiping Dai, Sangjian Chen
{"title":"Detection of Android Malware Behavior in Browser Downloads","authors":"Min-Hao Wu, Limin Yi, Ting-Cheng Chang, Yiwan Chen, Caiping Dai, Sangjian Chen","doi":"10.1109/ECBIOS54627.2022.9944991","DOIUrl":null,"url":null,"abstract":"Hypertext transfer protocol has become one of the most widely used Internet or industrial control systems, so protecting Web services is critical. Many information security research institutions deploy honeypots to collect network packets and analyze the software services and methods for the attack to understand the hacker's attack behavior. However, in analyzing the log, the analyst may face the problem of massive data volume and repeated inspection. Therefore, the analyst needs a tool to detect whether many newly captured packets are new types to reduce the analysis log time. We propose a new exception detection method named 'Detect new exceptions for Web-server‘. It overcomes the characteristics of abnormal packets captured by honeypots, such as Diverse, Unlabeled, and Imbalanced, and learns historical strange packet behavior in a semi-supervised manner. Historical exception behavior models are built to detect whether newly captured packets are new-type exceptions. The discovery approach incorporated with a feature-based can accomplish the result of low false positives and typical false downsides. It is feasible to rapidly discover whether the recently caught packages are a new type of irregularity and determine the new sort of problem index, minimizing the moment and price of the evaluation procedure for analysts.","PeriodicalId":330175,"journal":{"name":"2022 IEEE 4th Eurasia Conference on Biomedical Engineering, Healthcare and Sustainability (ECBIOS)","volume":"58 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-05-27","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 IEEE 4th Eurasia Conference on Biomedical Engineering, Healthcare and Sustainability (ECBIOS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ECBIOS54627.2022.9944991","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Hypertext transfer protocol has become one of the most widely used Internet or industrial control systems, so protecting Web services is critical. Many information security research institutions deploy honeypots to collect network packets and analyze the software services and methods for the attack to understand the hacker's attack behavior. However, in analyzing the log, the analyst may face the problem of massive data volume and repeated inspection. Therefore, the analyst needs a tool to detect whether many newly captured packets are new types to reduce the analysis log time. We propose a new exception detection method named 'Detect new exceptions for Web-server‘. It overcomes the characteristics of abnormal packets captured by honeypots, such as Diverse, Unlabeled, and Imbalanced, and learns historical strange packet behavior in a semi-supervised manner. Historical exception behavior models are built to detect whether newly captured packets are new-type exceptions. The discovery approach incorporated with a feature-based can accomplish the result of low false positives and typical false downsides. It is feasible to rapidly discover whether the recently caught packages are a new type of irregularity and determine the new sort of problem index, minimizing the moment and price of the evaluation procedure for analysts.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
在浏览器下载中检测Android恶意软件行为
超文本传输协议已成为Internet或工业控制系统中应用最广泛的协议之一,因此保护Web服务至关重要。许多信息安全研究机构部署蜜罐收集网络数据包,分析攻击的软件服务和攻击方法,了解黑客的攻击行为。但是,在分析日志时,分析人员可能面临数据量大、重复检查的问题。因此,分析人员需要一个工具来检测新捕获的数据包是否为新类型,以减少分析日志的时间。我们提出了一种新的异常检测方法——“检测web服务器的新异常”。它克服了蜜罐捕获的异常报文的多样性(Diverse)、未标记(Unlabeled)、不均衡(Imbalanced)等特征,以半监督的方式学习历史奇怪报文行为。建立历史异常行为模型,检测新捕获的报文是否为新型异常。结合基于特征的发现方法可以实现低误报和典型误降的结果。快速发现最近捕获的包裹是否为新的不规范类型并确定新的问题指标是可行的,最大限度地减少了分析人员评估过程的时间和代价。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Detection of Android Malware Behavior in Browser Downloads Breast Tumor Detection Using Multi-Channel 62-69 GHz Millimeter-wave 3D Imaging Technology Implementation and Design of Physical/Digital Switches Modified from Sonoff Product Based on Internet of Things Design of Intelligent Energy-Saving Controller Using Faucet Supercritical Carbon Dioxide Decellularized Porcine Dermal Matrix Accelerated Gingival Keratinization by Modified Apically Positioned Flap Technique
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1