Byakko: Automatic Whitelist Generation based on Occurrence Distribution of Features of Network Traffic

Nobuyuki Kanaya, Yu Tsuda, Yuuki Takano, Daisuke Inoue · 2019

In security operations such as incident response and malware analysis, a large number of logs are gathered from a monitoring network. These logs include security appliance alerts and network communications. Security operators must then find remarkable logs from all these logs. To filter out benign logs from all the logs, security operators commonly use a whitelist, which is a set of benign hosts decided upon by the security operators. When creating a whitelist, security operators typically refer to website-ranking services, the features of a monitoring network topology, their knowledge and expertise about the monitoring network, etc. In contrast, a whitelist should be continuously and manually updated by the security operators; thus, maintaining the whitelist places a higher burden on them. Therefore, in this paper, we propose Byakko, which is a method for automatically generating a whitelist based on statistical features, that is, occurrence distribution and its standard deviation. These features describe the stationarity of communications in a monitoring network. If a host has stationary communications, Byakko decides that the host must be benign. To evaluate Byakko, we conduct a performance evaluation and two case studies, which are for incident responses on an office network and for malware analysis on an analysis network. Our results show that Byakko is a practical method and can be applied to other cases as well.

Read the paper · More papers on PaperTik