A Self-Feedback Malware Detecting System based on HTTP Traffic
Minjie Zhu, Yilian Zhang, Yan Chen · 2021 International Conference on Intelligent Computing, Automation and Systems (ICICAS) · 2021
As one of the major threats to the Internet, malware has many variants and is difficult to detect. This paper proposes a HTTP traffic based self-feedback malware detecting system, aiming to overcome the weakness of traditional detection methods in terms of detection range, work efficiency, accuracy and adaptability to environmental changes. We first capture and analyze HTTP traffic by a selected time window. Then, we pre-process the captured traffic into streams. WebGraphic request algorithm is used to remove HTTP traffic generating by Web browsers. In order to avoid repeated processing of data, a fingerprint detection algorithm is used to identify similar traffic. We apply a deep learning algorithm to automatically extract features. Transfer learning and feedback learning strategy are also implemented to improve the detection effect, enabling the model to adapt to the changing network environment. We use the real-world dataset from campus traffic and experiments show that this system can efficiently and effectively detect malwares. In addition, the clustering of streams based on IP field and User-Agent field makes the granularity of malware object finer, which helps making the locating and tracing of malwares in Application level instead of IP level possible.