Back to search

George Mason University

A Deep Learning based Real-Time Detection of Stealthy Command and Control (C&C) Activities from Encrypted Traffic

Abstract

A Command and Control server is a malicious server used by the attacker to operate the victim machine from a remote location. The attacker can use this to execute persistent attacks on the victim network, upload or download files and execute processes on the victim computer. Detection of these Command and Control server activities in a network is substantially difficult as the network traffic it uses to communicate with the victim involves common HTTPS traffic. There are several attempts that were done at detecting the threats at the network level but either they were mostly related to the postmortem threat analysis or are based on known network traffic. These techniques are ineffective in detecting real world threats as they cannot prevent the attacks in real time. Through this thesis I explored the possibility of real time detection of the stealthy Command & Control servers in a commercial network environment. I present novel network feature set that can be collected in real time and be used for prediction of Command and Control activities in the network. The proposed approach is rigorously tested with real world data and yielded a true positive rate of 67% and a false positive rate of 0.07% on Cobalt strike C2 server.

Author and committee

dc:creator, dc:contributor.*
Author
  • Kandalam, Ramanuja Phani Vishnu Teja

Subjects

dc:subject × 6

Identifiers

dc:identifier.*
Identifier
hdl:1920/14647
OAI identifier oai:identifier
oai:MARS:1920/14647

Chain of custody

source
Harvested from
George Mason University
Base URL
mars.gmu.edu/server/oai/request
Last updated
2026-07-27
Source record
OAI-PMH GetRecord
citation

Kandalam, Ramanuja Phani Vishnu Teja. A Deep Learning based Real-Time Detection of Stealthy Command and Control (C&C) Activities from Encrypted Traffic. 2025.