Anatomy on Malware Distribution Networks

Sung-Jin Kim · IEEE Access · 2020

Malware distribution networks are a huge network that involves in malware distribution. We do not much realize the seriousness of the network in daily life. Until now, the works to analyze the network have been studied, but they are still limited because many researchers focused on detection, not investigating the internal structures of malware distribution networks. In this circumstance, the recent works tried to analyze the malware distribution networks in terms of social network analysis based on graph theories. They analyzed the malware distribution networks with nodes used in malware distribution such as malicious URLs, FQDN, malware and IPs, generated during drive-by downloads, or appeared outbound contacts. However, this approach is still lack in understandings malware distribution networks. In this study, we realized that$degree$(or$closeness$,$betweenness$, or$eigenvector$)$centrality~measures$are beneficial in finding central nodes engaging in malware distribution. This central information is by far valuable in understanding the properties of malicious network infrastructure. For instance, from$degree~centrality~measures$, we realized that malware distribution networks show high in-degree, while benign networks present high out-degree. This result offers artifacts that classify malicious networks from benign networks. After all, this study provides fundamental information to help distinguish heterogeneous networks useful in future research.

Read the paper · More papers on PaperTik