On correlating network traffic for cyber threat intelligence: A Bloom filter approach
Adil Atifi, Elias Bou‐Harb · 2017
Internet and organizational network security is still threatened by devastating malicious activities. Given the continuous escalation of such attacks in terms of their frequency, sophistication and stealthiness, it is of paramount importance to generate effective cyber threat intelligence that aims at inferring, attributing, characterizing and mitigating such misdemeanors. Nevertheless, such imperative tasks are partially impeded by the lack of correlation approaches that can produce prompt and accurate actionable intelligence by investigating various network traffic sources. To this end, this paper proposes a simple yet effective approach to generically correlate network traffic for cyber security purposes. The approach uniquely exploits Bloom filters to infer similarities between the analyzed network traffic while eliminating false negatives and managing a very low and a measurable false positive rate. We demonstrate the effectiveness of the proposed approach by empirically evaluating it using 10 GB of real darknet data and close to 15 thousand malware traffic samples. The outcome is rendered by hundreds of inferred and attributed Internet-scale infections, which we corroborate using third-party publicly accessible threat repositories. We envision that the proposed approach could be leveraged as an effective correlation component in complex security information and event management systems to provide metrics that would aid in characterizing and comprehending various network security activities and incidents.