{"id":{"repo_id":"gmu","oai_identifier":"oai:MARS:1920/14647"},"canonical_url":"https://search.dev.ndltd.org/etd/gmu/oai:MARS:1920/14647","repository":{"repo_id":"gmu","name":"George Mason University","base_url":"https://mars.gmu.edu/server/oai/request"},"display":{"title":"A Deep Learning based Real-Time Detection of Stealthy Command and Control (C&C) Activities from Encrypted Traffic","abstract":"A Command and Control server is a malicious server used by the attacker to operate the victim machine from a remote location. The attacker can use this to execute persistent attacks on the victim network, upload or download files and execute processes on the victim computer. Detection of these Command and Control server activities in a network is substantially difficult as the network traffic it uses to communicate with the victim involves common HTTPS traffic. There are several attempts that were done at detecting the threats at the network level but either they were mostly related to the postmortem threat analysis or are based on known network traffic. These techniques are ineffective in detecting real world threats as they cannot prevent the attacks in real time. Through this thesis I explored the possibility of real time detection of the stealthy Command & Control servers in a commercial network environment. I present novel network feature set that can be collected in real time and be used for prediction of Command and Control activities in the network. The proposed approach is rigorously tested with real world data and yielded a true positive rate of 67% and a false positive rate of 0.07% on Cobalt strike C2 server.","abstract_html":"A Command and Control server is a malicious server used by the attacker to operate the victim machine from a remote location. The attacker can use this to execute persistent attacks on the victim network, upload or download files and execute processes on the victim computer. Detection of these Command and Control server activities in a network is substantially difficult as the network traffic it uses to communicate with the victim involves common HTTPS traffic. There are several attempts that were done at detecting the threats at the network level but either they were mostly related to the postmortem threat analysis or are based on known network traffic. These techniques are ineffective in detecting real world threats as they cannot prevent the attacks in real time. Through this thesis I explored the possibility of real time detection of the stealthy Command &amp; Control servers in a commercial network environment. I present novel network feature set that can be collected in real time and be used for prediction of Command and Control activities in the network. The proposed approach is rigorously tested with real world data and yielded a true positive rate of 67% and a false positive rate of 0.07% on Cobalt strike C2 server.","abstract_has_math":false,"creators":["Kandalam, Ramanuja Phani Vishnu Teja"],"institution":null,"degree_name":null,"degree_level":null,"degree_discipline":null,"degree_department":null,"school":null,"contributors":[],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2025,"date_issued":"2025-05-01","date_published":"2025-05-01","updated_at":"2026-07-27T19:51:46Z","subjects":["Recurrent Neural Networks","Sliver","Intrusion Detection","Cobalt Strike","Command and Control","Deep learning"],"languages":[],"rights":[],"rights_urls":[],"identifier_entries":[{"key":"dc:identifier","label":"Identifier","values":["hdl:1920/14647"],"render_values":[{"text":"hdl:1920/14647","href":null,"code":true}]}]},"links":{"outbound_url":null,"outbound_label":null,"outbound_source":null},"metadata_groups":[{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.issued","label":"Date","values":["2025-05-01"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Recurrent Neural Networks","Sliver","Intrusion Detection","Cobalt Strike","Command and Control","Deep learning"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["hdl:1920/14647"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.other","label":"Dc Description Other","values":["A Command and Control server is a malicious server used by the attacker to operate the victim machine from a remote location. The attacker can use this to execute persistent attacks on the victim network, upload or download files and execute processes on the victim computer. Detection of these Command and Control server activities in a network is substantially difficult as the network traffic it uses to communicate with the victim involves common HTTPS traffic. There are several attempts that were done at detecting the threats at the network level but either they were mostly related to the postmortem threat analysis or are based on known network traffic. These techniques are ineffective in detecting real world threats as they cannot prevent the attacks in real time. Through this thesis I explored the possibility of real time detection of the stealthy Command & Control servers in a commercial network environment. I present novel network feature set that can be collected in real time and be used for prediction of Command and Control activities in the network. The proposed approach is rigorously tested with real world data and yielded a true positive rate of 67% and a false positive rate of 0.07% on Cobalt strike C2 server."]},{"key":"dc:title","label":"Title","values":["A Deep Learning based Real-Time Detection of Stealthy Command and Control (C&C) Activities from Encrypted Traffic"]}]}],"canonical_facts":{"dc:date.issued":["2025-05-01"],"dc:description.other":["A Command and Control server is a malicious server used by the attacker to operate the victim machine from a remote location. The attacker can use this to execute persistent attacks on the victim network, upload or download files and execute processes on the victim computer. Detection of these Command and Control server activities in a network is substantially difficult as the network traffic it uses to communicate with the victim involves common HTTPS traffic. There are several attempts that were done at detecting the threats at the network level but either they were mostly related to the postmortem threat analysis or are based on known network traffic. These techniques are ineffective in detecting real world threats as they cannot prevent the attacks in real time. Through this thesis I explored the possibility of real time detection of the stealthy Command & Control servers in a commercial network environment. I present novel network feature set that can be collected in real time and be used for prediction of Command and Control activities in the network. The proposed approach is rigorously tested with real world data and yielded a true positive rate of 67% and a false positive rate of 0.07% on Cobalt strike C2 server."],"dc:identifier":["hdl:1920/14647"],"dc:subject":["Recurrent Neural Networks","Sliver","Intrusion Detection","Cobalt Strike","Command and Control","Deep learning"],"dc:title":["A Deep Learning based Real-Time Detection of Stealthy Command and Control (C&C) Activities from Encrypted Traffic"],"dc:type":["Thesis"]},"updated_at":"2026-07-27T19:51:46Z"}