C2-based Malware Detection Through Network Analysis Using Machine Learning
Martin Martijan, Virgilijus Krinickij, Linas Bukauskas · 2025
The increasing sophistication of cyber threats, particularly those leveraging Command-and-Control (C2) infrastructures, poses significant challenges to traditional detection mechanisms. While machine learning (ML) has been explored for network anomaly detection, many existing approaches rely on outdated datasets or place less emphasis on the importance of feature engineering for distinguishing malware traffic. This research aims to improve malware classification by focusing on malware-specific characteristics and applying feature engineering techniques to enhance datasets, enabling ML models to classify malicious traffic with greater accuracy. Additionally, different dataset labelling strategies were examined to determine whether it is better to focus on infection indicators of compromise (IoC) only, or the whole communication between an adversary and the victim. The models are trained on real captured malware datasets, which have been refined with malware-specific engineered features to enhance detection capabilities. The work presents indicative results that Random Forest and Extreme Gradient Boosting classifiers achieve over $98 \%$ accuracy in identifying malware families such as WarmCookie, FormBook, and AgentTesla using malware-unique network-based parameters. These findings contribute to advancing intrusion detection systems (IDS) by providing an automated, network-based threat detection methodology.