Real-time Fingerprints Embedding Method for Malicious Encrypted Traffic Analysis

Wei Li, Zhong Guan · 2024

The traffic encryption technology protects the privacy of network users. Meanwhile, it also provides convenience for illegal cyberspace activities such as malicious attacks. Since no plain-text information exposed, network administrators have no idea whether the network traffic is malicious or where attackers come from. Therefore, encrypted malicious traffic analysis methods are put forward for ensuring the network security. These methods aim at finding out abnormal traffic among received data flows, and even find the source of abnormal traffic in the other end of networks. However, existing methods follow the passive manner which totally depends on traffic’s own features, thus having a poor effectiveness since malicious traffic usually does not reveal too many distinguished features. To solve this problem, we put forward an active analysis method based on the real-time traffic fingerprints embedding, enhancing the capability of encrypted malicious traffic analysis. Firstly, we insert the signal into the traffic toward all suspicious attackers’ side, then detect the embedded traffic from the received data of victims, finally extract the signal from detected samples and compare the signal similarity. Once the similarity meets the standard, we can confirm the end-to-end communication relationships involved in malicious network behaviors. Experiment results show that the active analysis way has obviously better results.

Read the paper · More papers on PaperTik