Novel TLS Signature Extraction for Malware Detection

Kuang-Hua Pai, Shubhodeep Mitra, Madhusoodhana Chari S. · 2020

Encryption is the key to network security and privacy. The rapid growth and use of encrypted traffic in the network has inadvertently facilitated malware to adopt encryption and traverse undetected through the network infecting the victim. This paper presents a solution to identify the presence of malware in a network flow from the initial unencrypted Client Hello packet of TLS handshake.We perform feature engineering on the subfields of TLS metadata of Client Hello packet to extract interpretable signatures in the form of numerical features. These features can be effectively used to model a binary classifier and assign a risk score to indicate the presence of malware. This classifier can be deployed at the EDGE for passive monitoring and malicious flows can be redirected to the cloud for deeper inspection.

Read the paper · More papers on PaperTik