Detecting Malicious Traffic using JA3 Fingerprints Attributed ML Approach

Yuba R. Siwakoti, Danda B. Rawat · 2024

Security challenges are constantly rising due to the rapidly increasing Internet of Things (IoT) deployment in diverse fields. To minimize such challenges, our study focuses on improving IoT security by detecting malicious traffic with an ML-based approach using JA3 signatures. We consider IoT and non-IoT traffic and contribute insights to existing IoT security literature by proposing a unique detection approach where JA3 signatures are used as machine learning (ML) model features. Leveraging machine learning and deep learning (DL) models such as decision trees (DT), random forests (RF), artificial neural networks (ANN), and ensemble (ENS) models, the approach demonstrates high detection rates. Though all models performed well, the ensemble model, which counts the majority of predictions of the other three models, consistently excelled with an accuracy of 0.964, recall (detection rate) of 0.992, a precision of 0.944, and an F1-score of 0.967. These results demonstrate the robustness of our ML-based detection approach using JA3 signatures in augmenting threat detection capabilities. Our approach contributes to developing robust cybersecurity strategies for safeguarding the ever-evolving landscapes of IoT. Although the performances are promising, identified limitations related to JA3 collision and impersonation emphasize the need to integrate this approach into existing defensive arsenals.

Read the paper · More papers on PaperTik