The Experts below are selected from a list of 2439 Experts worldwide ranked by ideXlab platform

Manos Antonakakis - One of the best experts on this subject based on the ideXlab platform.

  • ESORICS - Measuring and Detecting Malware Downloads in Live Network Traffic
    Lecture Notes in Computer Science, 2013
    Co-Authors: Phani Vadrevu, Roberto Perdisci, Babak Rahbarinia, Kang Li, Manos Antonakakis
    Abstract:

    In this paper, we present AMICO, a novel system for measuring and Detecting Malware downloads in live web traffic. AMICO learns to distinguish between Malware and benign file downloads from the download behavior of the network users themselves. Given a labeled dataset of past benign and Malware file downloads, AMICO learns a provenance classifier that can accurately detect future Malware downloads based on information about where the downloads originated from. The main intuition is that to avoid current countermeasures, Malware campaigns need to use an “agile” distribution infrastructure, e.g., frequently changing the domains and/or IPs of the Malware download servers. We engineer a number of statistical features that aim to capture these fundamental characteristics of Malware distribution campaigns.

  • measuring and Detecting Malware downloads in live network traffic
    European Symposium on Research in Computer Security, 2013
    Co-Authors: Phani Vadrevu, Roberto Perdisci, Babak Rahbarinia, Kang Li, Manos Antonakakis
    Abstract:

    In this paper, we present AMICO, a novel system for measuring and Detecting Malware downloads in live web traffic. AMICO learns to distinguish between Malware and benign file downloads from the download behavior of the network users themselves. Given a labeled dataset of past benign and Malware file downloads, AMICO learns a provenance classifier that can accurately detect future Malware downloads based on information about where the downloads originated from. The main intuition is that to avoid current countermeasures, Malware campaigns need to use an “agile” distribution infrastructure, e.g., frequently changing the domains and/or IPs of the Malware download servers. We engineer a number of statistical features that aim to capture these fundamental characteristics of Malware distribution campaigns.

  • USENIX Security Symposium - Detecting Malware domains at the upper DNS hierarchy
    2011
    Co-Authors: Manos Antonakakis, Roberto Perdisci, Nikolaos Vasiloglou, David Dagon
    Abstract:

    In recent years Internet miscreants have been leveraging the DNS to build malicious network infrastructures for Malware command and control. In this paper we propose a novel detection system called Kopis for Detecting Malware-related domain names. Kopis passively monitors DNS traffic at the upper levels of the DNS hierarchy, and is able to accurately detect Malware domains by analyzing global DNS query resolution patterns. Compared to previous DNS reputation systems such as Notos [3] and Exposure [4], which rely on monitoring traffic from local recursive DNS servers, Kopis offers a new vantage point and introduces new traffic features specifically chosen to leverage the global visibility obtained by monitoring network traffic at the upper DNS hierarchy. Unlike previous work Kopis enables DNS operators to independently (i.e., without the need of data from other networks) detect Malware domains within their authority, so that action can be taken to stop the abuse. Moreover, unlike previous work, Kopis can detect Malware domains even when no IP reputation information is available. We developed a proof-of-concept version of Kopis, and experimented with eight months of real-world data. Our experimental results show that Kopis can achieve high detection rates (e.g., 98.4%) and low false positive rates (e.g., 0.3% or 0.5%). In addition Kopis is able to detect new Malware domains days or even weeks before they appear in public blacklists and security forums, and allowed us to discover the rise of a previously unknown DDoS botnet based in China.

  • Detecting Malware Domains at the Upper DNS Hierarchy
    USENIX Security Symposium., 2011
    Co-Authors: Manos Antonakakis, Nikolaos Vasiloglou Ii, Roberto Perdisci, Wenke Lee, David Dagon
    Abstract:

    In recent years Internet miscreants have been leveraging the DNS to build malicious network infrastructures for Malware command and control. In this paper we pro- pose a novel detection system called Kopis for Detecting Malware-related domain names. Kopis passively moni- tors DNS traffic at the upper levels of the DNS hierar- chy, and is able to accurately detect Malware domains by analyzing global DNS query resolution patterns.Compared to previous DNS reputation systems such as Notos 3 and Exposure 4, which rely on monitor- ing traffic from local recursive DNS servers, Kopis offers a new vantage point and introduces new traffic features specifically chosen to leverage the global visibility ob- tained by monitoring network traffic at the upper DNS hi- erarchy. Unlike previous work Kopis enables DNS oper- ators to independently (i.e., without the need of data from other networks) detect Malware domains within their au- thority, so that action can be taken to stop the abuse. Moreover, unlike previous work, Kopis can detect mal- ware domains even when no IP reputation information is available.We developed a proof-of-concept version of Kopis, and experimented with eight months of real-world data. Our experimental results show that Kopis can achieve high detection rates (e.g., 98.4%) and low false positive rates (e.g., 0.3% or 0.5%). In addition Kopis is able to detect new Malware domains days or even weeks before they appear in public blacklists and security forums, and allowed us to discover the rise of a previously unknown DDoS botnet based in China.

Wenke Lee - One of the best experts on this subject based on the ideXlab platform.

  • Detecting Malware Domains at the Upper DNS Hierarchy
    USENIX Security Symposium., 2011
    Co-Authors: Manos Antonakakis, Nikolaos Vasiloglou Ii, Roberto Perdisci, Wenke Lee, David Dagon
    Abstract:

    In recent years Internet miscreants have been leveraging the DNS to build malicious network infrastructures for Malware command and control. In this paper we pro- pose a novel detection system called Kopis for Detecting Malware-related domain names. Kopis passively moni- tors DNS traffic at the upper levels of the DNS hierar- chy, and is able to accurately detect Malware domains by analyzing global DNS query resolution patterns.Compared to previous DNS reputation systems such as Notos 3 and Exposure 4, which rely on monitor- ing traffic from local recursive DNS servers, Kopis offers a new vantage point and introduces new traffic features specifically chosen to leverage the global visibility ob- tained by monitoring network traffic at the upper DNS hi- erarchy. Unlike previous work Kopis enables DNS oper- ators to independently (i.e., without the need of data from other networks) detect Malware domains within their au- thority, so that action can be taken to stop the abuse. Moreover, unlike previous work, Kopis can detect mal- ware domains even when no IP reputation information is available.We developed a proof-of-concept version of Kopis, and experimented with eight months of real-world data. Our experimental results show that Kopis can achieve high detection rates (e.g., 98.4%) and low false positive rates (e.g., 0.3% or 0.5%). In addition Kopis is able to detect new Malware domains days or even weeks before they appear in public blacklists and security forums, and allowed us to discover the rise of a previously unknown DDoS botnet based in China.

  • BotHunter: Detecting Malware infection through IDS-driven dialog correlation
    USENIX Security '07 Proceedings of the 16th USENIX Security Symposium, 2007
    Co-Authors: Guofei Gu, Martin Fong, Vinod Yegneswaran, Phillip Porras, Wenke Lee
    Abstract:

    - Zur Erkennung von Bot-Infektionen wird die "Dialog Correlation"-Strategie vorgestellt, die meiner Kill-Chain-Idee ähnlich ist - Es werden verschiedene Netzwerk-basierte Features genutzt (keine Host Features)

Martin Fong - One of the best experts on this subject based on the ideXlab platform.

  • bothunter Detecting Malware infection through ids driven dialog correlation
    USENIX Security Symposium, 2007
    Co-Authors: Guofei Gu, Vinod Yegneswaran, Phillip Porras, Martin Fong
    Abstract:

    We present a new kind of network perimeter monitoring strategy, which focuses on recognizing the infection and coordination dialog that occurs during a successful Malware infection. BotHunter is an application designed to track the two-way communication flows between internal assets and external entities, developing an evidence trail of data exchanges that match a state-based infection sequence model. BotHunter consists of a correlation engine that is driven by three Malware-focused network packet sensors, each charged with Detecting specific stages of the Malware infection process, including inbound scanning, exploit usage, egg downloading, outbound bot coordination dialog, and outbound attack propagation. The BotHunter correlator then ties together the dialog trail of inbound intrusion alarms with those outbound communication patterns that are highly indicative of successful local host infection. When a sequence of evidence is found to match BotHunter's infection dialog model, a consolidated report is produced to capture all the relevant events and event sources that played a role during the infection process. We refer to this analytical strategy of matching the dialog flows between internal assets and the broader Internet as dialog-based correlation, and contrast this strategy to other intrusion detection and alert correlation methods. We present our experimental results using BotHunter in both virtual and live testing environments, and discuss our Internet release of the BotHunter prototype. BotHunter is made available both for operational use and to help stimulate research in understanding the life cycle of Malware infections.

  • BotHunter: Detecting Malware infection through IDS-driven dialog correlation
    USENIX Security '07 Proceedings of the 16th USENIX Security Symposium, 2007
    Co-Authors: Guofei Gu, Martin Fong, Vinod Yegneswaran, Phillip Porras, Wenke Lee
    Abstract:

    - Zur Erkennung von Bot-Infektionen wird die "Dialog Correlation"-Strategie vorgestellt, die meiner Kill-Chain-Idee ähnlich ist - Es werden verschiedene Netzwerk-basierte Features genutzt (keine Host Features)

Roberto Perdisci - One of the best experts on this subject based on the ideXlab platform.

  • ESORICS - Measuring and Detecting Malware Downloads in Live Network Traffic
    Lecture Notes in Computer Science, 2013
    Co-Authors: Phani Vadrevu, Roberto Perdisci, Babak Rahbarinia, Kang Li, Manos Antonakakis
    Abstract:

    In this paper, we present AMICO, a novel system for measuring and Detecting Malware downloads in live web traffic. AMICO learns to distinguish between Malware and benign file downloads from the download behavior of the network users themselves. Given a labeled dataset of past benign and Malware file downloads, AMICO learns a provenance classifier that can accurately detect future Malware downloads based on information about where the downloads originated from. The main intuition is that to avoid current countermeasures, Malware campaigns need to use an “agile” distribution infrastructure, e.g., frequently changing the domains and/or IPs of the Malware download servers. We engineer a number of statistical features that aim to capture these fundamental characteristics of Malware distribution campaigns.

  • measuring and Detecting Malware downloads in live network traffic
    European Symposium on Research in Computer Security, 2013
    Co-Authors: Phani Vadrevu, Roberto Perdisci, Babak Rahbarinia, Kang Li, Manos Antonakakis
    Abstract:

    In this paper, we present AMICO, a novel system for measuring and Detecting Malware downloads in live web traffic. AMICO learns to distinguish between Malware and benign file downloads from the download behavior of the network users themselves. Given a labeled dataset of past benign and Malware file downloads, AMICO learns a provenance classifier that can accurately detect future Malware downloads based on information about where the downloads originated from. The main intuition is that to avoid current countermeasures, Malware campaigns need to use an “agile” distribution infrastructure, e.g., frequently changing the domains and/or IPs of the Malware download servers. We engineer a number of statistical features that aim to capture these fundamental characteristics of Malware distribution campaigns.

  • USENIX Security Symposium - Detecting Malware domains at the upper DNS hierarchy
    2011
    Co-Authors: Manos Antonakakis, Roberto Perdisci, Nikolaos Vasiloglou, David Dagon
    Abstract:

    In recent years Internet miscreants have been leveraging the DNS to build malicious network infrastructures for Malware command and control. In this paper we propose a novel detection system called Kopis for Detecting Malware-related domain names. Kopis passively monitors DNS traffic at the upper levels of the DNS hierarchy, and is able to accurately detect Malware domains by analyzing global DNS query resolution patterns. Compared to previous DNS reputation systems such as Notos [3] and Exposure [4], which rely on monitoring traffic from local recursive DNS servers, Kopis offers a new vantage point and introduces new traffic features specifically chosen to leverage the global visibility obtained by monitoring network traffic at the upper DNS hierarchy. Unlike previous work Kopis enables DNS operators to independently (i.e., without the need of data from other networks) detect Malware domains within their authority, so that action can be taken to stop the abuse. Moreover, unlike previous work, Kopis can detect Malware domains even when no IP reputation information is available. We developed a proof-of-concept version of Kopis, and experimented with eight months of real-world data. Our experimental results show that Kopis can achieve high detection rates (e.g., 98.4%) and low false positive rates (e.g., 0.3% or 0.5%). In addition Kopis is able to detect new Malware domains days or even weeks before they appear in public blacklists and security forums, and allowed us to discover the rise of a previously unknown DDoS botnet based in China.

  • Detecting Malware Domains at the Upper DNS Hierarchy
    USENIX Security Symposium., 2011
    Co-Authors: Manos Antonakakis, Nikolaos Vasiloglou Ii, Roberto Perdisci, Wenke Lee, David Dagon
    Abstract:

    In recent years Internet miscreants have been leveraging the DNS to build malicious network infrastructures for Malware command and control. In this paper we pro- pose a novel detection system called Kopis for Detecting Malware-related domain names. Kopis passively moni- tors DNS traffic at the upper levels of the DNS hierar- chy, and is able to accurately detect Malware domains by analyzing global DNS query resolution patterns.Compared to previous DNS reputation systems such as Notos 3 and Exposure 4, which rely on monitor- ing traffic from local recursive DNS servers, Kopis offers a new vantage point and introduces new traffic features specifically chosen to leverage the global visibility ob- tained by monitoring network traffic at the upper DNS hi- erarchy. Unlike previous work Kopis enables DNS oper- ators to independently (i.e., without the need of data from other networks) detect Malware domains within their au- thority, so that action can be taken to stop the abuse. Moreover, unlike previous work, Kopis can detect mal- ware domains even when no IP reputation information is available.We developed a proof-of-concept version of Kopis, and experimented with eight months of real-world data. Our experimental results show that Kopis can achieve high detection rates (e.g., 98.4%) and low false positive rates (e.g., 0.3% or 0.5%). In addition Kopis is able to detect new Malware domains days or even weeks before they appear in public blacklists and security forums, and allowed us to discover the rise of a previously unknown DDoS botnet based in China.

Guofei Gu - One of the best experts on this subject based on the ideXlab platform.

  • bothunter Detecting Malware infection through ids driven dialog correlation
    USENIX Security Symposium, 2007
    Co-Authors: Guofei Gu, Vinod Yegneswaran, Phillip Porras, Martin Fong
    Abstract:

    We present a new kind of network perimeter monitoring strategy, which focuses on recognizing the infection and coordination dialog that occurs during a successful Malware infection. BotHunter is an application designed to track the two-way communication flows between internal assets and external entities, developing an evidence trail of data exchanges that match a state-based infection sequence model. BotHunter consists of a correlation engine that is driven by three Malware-focused network packet sensors, each charged with Detecting specific stages of the Malware infection process, including inbound scanning, exploit usage, egg downloading, outbound bot coordination dialog, and outbound attack propagation. The BotHunter correlator then ties together the dialog trail of inbound intrusion alarms with those outbound communication patterns that are highly indicative of successful local host infection. When a sequence of evidence is found to match BotHunter's infection dialog model, a consolidated report is produced to capture all the relevant events and event sources that played a role during the infection process. We refer to this analytical strategy of matching the dialog flows between internal assets and the broader Internet as dialog-based correlation, and contrast this strategy to other intrusion detection and alert correlation methods. We present our experimental results using BotHunter in both virtual and live testing environments, and discuss our Internet release of the BotHunter prototype. BotHunter is made available both for operational use and to help stimulate research in understanding the life cycle of Malware infections.

  • BotHunter: Detecting Malware infection through IDS-driven dialog correlation
    USENIX Security '07 Proceedings of the 16th USENIX Security Symposium, 2007
    Co-Authors: Guofei Gu, Martin Fong, Vinod Yegneswaran, Phillip Porras, Wenke Lee
    Abstract:

    - Zur Erkennung von Bot-Infektionen wird die "Dialog Correlation"-Strategie vorgestellt, die meiner Kill-Chain-Idee ähnlich ist - Es werden verschiedene Netzwerk-basierte Features genutzt (keine Host Features)