Revisiting TLS-Encrypted Traffic Fingerprinting Methods for Malware Family Classification
Hyundo Kim, Minsu Kim, Joonseo Ha, Heejun Roh · 2022 13th International Conference on Information and Communication Technology Convergence (ICTC) · 2022
Transport Layer Security (TLS) is a well-known end-to-end encryption protocol for secure communication, and the use of TLS is continuously increasing, which influences that currently most of the Web traffic is delivered through a secure channel. Unfortunately, the use of secure channel for malware is also substantially increasing so that both application layer payload and metadata from unencrypted header fields become unavailable for malicious traffic classification. While several TLS fingerprinting methods, namely JA3 and Mercury, are available, the approaches are more suitable for exact matching than for machine learning-based classification. To deal with this, in this paper, we revisit Markov chain-based fingerprinting from packet length sequences to classify TLS-encrypted malware traffic into malware families. We especially, evaluate Markov chain-based and the existing fingerprinting methods (JA3 and Mercury) with several classifiers including k-nearest neighbor and convolutional neural network. Our results show that our Markov chain-based approach has better performance than other fingerprinting methods with an appropriate classifier.