Detecting malware infected devices by discriminating legitimate from malicious traffic using HTTP protocol
EWIT · International Journal of Computing Communications and Networking · 2018
Malware causes a huge damage is one of the serious problems that has to be identified.The evasion malware spread in recent times made it difficult to detect in pre-infection time.The best approach is malware detection at post-infection timing.By monitoring the internet traffic this work aims to identify the malware-infected devices.Most of the malware uses the internet as a means to communicate with the command and control servers which is located on the external network, the recorded HTTP headers information is monitored to discriminate between the legitimate and malicious traffic.This method is scalable and robust because it uses automatic template generation which will reduce most amount of information that has to be kept while obtaining high accuracy in classification.We us several classifiers, which makes use of extracted templates and classifies traffic into two categories: malicious and legitimate.