WebEye - Automated Collection of Malicious HTTP Traffic
With malware detection techniques increasingly adopting machine learning approaches, the creation of precise training sets becomes more and more important. Large data sets of realistic web traffic, correctly classified as benign or malicious are needed, not only to train classic and deep learning algorithms, but also to serve as evaluation benchmarks for existing malware detection products. Interestingly, despite the vast number and versatility of threats a user may encounter when browsing the web, actual malicious content is often hard to come by, since prerequisites such as browser and operating system type and version must be met in order to receive the payload from a malware distributing server. In combination with privacy constraints on data sets of actual user traffic, it is difficult for researchers and product developers to evaluate anti-malware solutions against large-scale data sets of realistic web traffic. In this paper we present WebEye, a framework that autonomously creates realistic HTTP traffic, enriches recorded traffic with additional information, and classifies records as malicious or benign, using different classifiers. We are using WebEye to collect malicious HTML and JavaScript and show how datasets created with WebEye can be used to train machine learning based malware detection algorithms. We regard WebEye and the data sets it creates as a tool for researchers and product developers to evaluate and improve their AI-based anti-malware solutions against large-scale benchmarks.
Code (0)
등록된 구현이 없습니다.
Tasks
BIG-bench Machine LearningMalware DetectionSimilar Papers 제목 키워드 기반
WEBEYETRACK: Scalable Eye-Tracking for the Browser via On-Device Few-Shot Personalization
With advancements in AI, new gaze estimation methods are exceeding state-of-the-art (SOTA) benchmarks, but their real-world application reveals a gap with commercial eye-tracking solutions. Factors like model size, infer…
Head Pose EstimationFew-Shot LearningGaze EstimationFeature Analysis of Encrypted Malicious Traffic
In recent years there has been a dramatic increase in the number of malware attacks that use encrypted HTTP traffic for self-propagation or communication. Antivirus software and firewalls typically will not have access t…
ASNM Datasets: A Collection of Network Traffic Features for Testing of Adversarial Classifiers and Network Intrusion Detectors
In this paper, we present three datasets that have been built from network traffic traces using ASNM features, designed in our previous work. The first dataset was built using a state-of-the-art dataset called CDX 2009, …
Intrusion DetectionNetwork Intrusion DetectionETGuard: Malicious Encrypted Traffic Detection in Blockchain-based Power Grid Systems
The escalating prevalence of encryption protocols has led to a concomitant surge in the number of malicious attacks that hide in encrypted traffic. Power grid systems, as fundamental infrastructure, are becoming prime ta…
Incremental LearningPrivacy-Preserving Data-Enabled Predictive Leading Cruise Control in Mixed Traffic
Data-driven predictive control of connected and automated vehicles (CAVs) has received increasing attention as it can achieve safe and optimal control without relying on explicit dynamical models. However, employing the …
Privacy Preserving