Behaviour similarity based to cluster automated HTTP communication
Manh Cong Tran, Yasuhiro Nakamura · 2016
HTTP automated software (auto-ware) are blooming for multiple purposes due to the fast growing of World Wide Web. Beside normal HTTP application are beneficial for users such as operating system or virus definition update software, in recent years, cyber criminals turn to fully exploit web as a medium of communication environment to lurk variety of forbidden or illicit activities through spreading malicious automated software such as adware, spyware or bot. In addition, auto-ware traffic is almost anonymity to users. Therefore, in a private network, due to early detection of internal threats, clustering of auto-ware communication is helpful to network security management. In this paper, based on analysis of the auto-ware communication behaviour, a network level approach in clustering of HTTP auto-ware communication is proposed. The experimentation with real outbound HTTP traffic data which collected through a proxy server of a private network gives a considerable result in clustering HTTP auto-ware traffic. The results can be used as a good resource for further security purposes such as malicious domain/URL detection or investigation of HTTP based malware.