DESIGN AND DEVELOPMENT OF AN INTELLECTUAL AGENT FOR DETECTION OF CYBER THREATS AND MALWARE IN CORPORATE NETWORKS

Sergii Lysenko, Tetiana Kysil, Roman Shchuka · Herald of Khmelnytskyi National University Technical sciences · 2020

The purpose of this paper is to develop an intellectual agent for detection of cyber threats and malware in corporate networks – BotGRABBER. It provides a novel botnet detection framework with the key features given below: ability to detect the most known botnets’ cyberattacks; ability to detect the botnets that use the evasion techniques (cycling of IP mapping, “domain flux”, “fast flux” and DNS-tunneling); ability to self-adaptive appliance of the security scenarios for the cyberattacks mitigation, performed by botnets; assuring the corporate area networks’ resilience in the presence of botnets’ cyberattacks; assurance of the multi vector protection for corporate area networks. The main components of the intellectual agent are: Knowledge base. Knowledge base provides the information storage concerning to the cyberattacks performed by a botnet in the network and in the hosts. Here, each cyberattack is presented as the feature vector, which consists of functional botnets’ features. To increase the efficiency of the botnet detection each stage of possible botnet’s life cycle functioning (infection; initial registration or connection to C&C server; performance of the malicious activity; maintenance; its functioning termination) is presented by own feature vector. Knowledge acquisition unit. Taking into account the increasing of the new ways to perform the cyberattacks proposed tool is provided by ability to update the knowledge about new botnets. Network monitoring unit. This unit implements the network monitoring via gathering of the inbound and outbound network traffic. Collected information is converted into the feature vectors, and is sent to the SVM-based inference engine for further data processing. Host monitoring unit. This unit implements the gathering the information about the hosts’ network activity and reports of the hosts’ antiviruses. It also converts the collected information into the feature vectors, and sends it to the SVM-based inference engine for further data processing. SVM-based inference engine. This component provides an ability to classify the feature vectors obtained from the network. The main task of the SVM-based inference engine is to range obtained feature vector in a class, which will indicate whether it is cyberattacks, performed by botnet. If the attack is observed, the security scenario according to detected attack in order to mitigate it is to be applied. Network reconfiguration unit. This unit applies produced by the SVM-based inference engine the security scenario for the CAN’s infrastructure.

Read the paper · More papers on PaperTik