Back to results

Kennesaw State University

Fast and Accurate Machine Learning-based Malware Detection via RC4 Ciphertext Analysis

Abstract

dc:description.abstract

<p>Malware is dramatically increasing its viability while hiding its malicious intent and/or behavior by employing ciphers. So far, many efforts have been made to detect malware and prevent it from damaging users by monitoring network packets. However, conventional detection schemes analyzing network packets directly are hardly applicable to detect the advanced malware that encrypts the communication. Cryptoanalysis of each packet flowing over a network might be one feasible solution for the problem. However, the approach is computationally expensive and lacks accuracy, which is consequently not a practical solution. To tackle these problems, in this paper, we propose novel schemes that can accurately detect malware packets encrypted by RC4 without decryption in a timely manner. First, we discovered that a fixed encryption key generates unique statistical patterns on RC4 ciphertexts. Then, we detect malware packets of RC4 ciphertexts efficiently and accurately by utilizing the discovered statistical patterns of RC4 ciphertext given encryption key. Our proposed schemes directly analyze network packets without decrypting ciphertexts. Moreover, our analysis can be effectively executed with only a very small subset of the network packet. To the best of our knowledge, the unique signature has never been discussed in any previous research. Our intensive experimental results with both simulation data and actual malware show that our proposed schemes are extremely fast (23.06±1.52 milliseconds) and highly accurate (100%) on detecting a DarkComet malware with only a network packet of 36 bytes.</p>

Degree

thesis:*
Name thesis:degree_name
Master of Science in Computer Science (MSCS)
Level thesis:degree_level
Thesis
Discipline thesis:degree_discipline
Computer Science
Year dc:date.available
2018

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Ko, Euiseong
Contributors dc:contributor
  • Dr. Donghyun Kim
  • Dr. Chih-Cheng Hung

Subjects

dc:subject × 1

Identifiers

dc:identifier.*
Repository record dc:identifier
https://digitalcommons.kennesaw.edu/cs_etd/14
OAI identifier oai:identifier
oai:digitalcommons.kennesaw.edu:cs_etd-1017

Chain of custody

source
Harvested from
Kennesaw State University
Base URL
digitalcommons.kennesaw.edu/do/oai/
Last updated
2026-07-24
Source record
OAI-PMH GetRecord
citation

Ko, Euiseong. Fast and Accurate Machine Learning-based Malware Detection via RC4 Ciphertext Analysis. Thesis thesis, 2018. https://digitalcommons.kennesaw.edu/cs_etd/14