George Mason University
A Deep Learning based Real-Time Detection of Stealthy Command and Control (C&C) Activities from Encrypted Traffic
Abstract
A Command and Control server is a malicious server used by the attacker to operate the victim machine from a remote location. The attacker can use this to execute persistent attacks on the victim network, upload or download files and execute processes on the victim computer. Detection of these Command and Control server activities in a network is substantially difficult as the network traffic it uses to communicate with the victim involves common HTTPS traffic. There are several attempts that were done at detecting the threats at the network level but either they were mostly related to the postmortem threat analysis or are based on known network traffic. These techniques are ineffective in detecting real world threats as they cannot prevent the attacks in real time. Through this thesis I explored the possibility of real time detection of the stealthy Command & Control servers in a commercial network environment. I present novel network feature set that can be collected in real time and be used for prediction of Command and Control activities in the network. The proposed approach is rigorously tested with real world data and yielded a true positive rate of 67% and a false positive rate of 0.07% on Cobalt strike C2 server.
Author and committee
dc:creator, dc:contributor.*- Author
-
- Kandalam, Ramanuja Phani Vishnu Teja
Subjects
dc:subject × 6Identifiers
dc:identifier.*- Identifier
- hdl:1920/14647
- OAI identifier oai:identifier
- oai:MARS:1920/14647