• KSII Transactions on Internet and Information Systems
    Monthly Online Journal (eISSN: 1976-7277)

HAS-Analyzer: Detecting HTTP-based C&C based on the Analysis of HTTP Activity Sets

Vol. 8, No. 5, May 28, 2014
10.3837/tiis.2014.05.017, Download Paper (Free):

Abstract

Because HTTP-related ports are allowed through firewalls, they are an obvious point for launching cyber attacks. In particular, malware uses HTTP protocols to communicate with their master servers. We call this an HTTP-based command and control (C&C) server. Most previous studies concentrated on the behavioral pattern of C&Cs. However, these approaches need a well-defined white list to reduce the false positive rate because there are many benign applications, such as automatic update checks and web refreshes, that have a periodic access pattern. In this paper, we focus on finding new discriminative features of HTTP-based C&Cs by analyzing HTTP activity sets. First, a C&C shows a few connections at a time (low density). Second, the content of a request or a response is changed frequently among consecutive C&Cs (high content variability). Based on these two features, we propose a novel C&C analysis mechanism that detects the HTTP-based C&C. The HAS-Analyzer can classify the HTTP-based C&C with an accuracy of more than 96% and a false positive rate of 1.3% without using any white list.


Statistics

Show / Hide Statistics

Statistics (Cumulative Counts from December 1st, 2015)
Multiple requests among the same browser session are counted as one view.
If you mouse over a chart, the values of data points will be shown.


Cite this article

[IEEE Style]
S. Kim, S. Lee, B. Bae, "HAS-Analyzer: Detecting HTTP-based C&C based on the Analysis of HTTP Activity Sets," KSII Transactions on Internet and Information Systems, vol. 8, no. 5, pp. 1801-1816, 2014. DOI: 10.3837/tiis.2014.05.017.

[ACM Style]
Sung-Jin Kim, Sungryoul Lee, and Byungchul Bae. 2014. HAS-Analyzer: Detecting HTTP-based C&C based on the Analysis of HTTP Activity Sets. KSII Transactions on Internet and Information Systems, 8, 5, (2014), 1801-1816. DOI: 10.3837/tiis.2014.05.017.

[BibTeX Style]
@article{tiis:20529, title="HAS-Analyzer: Detecting HTTP-based C&C based on the Analysis of HTTP Activity Sets", author="Sung-Jin Kim and Sungryoul Lee and Byungchul Bae and ", journal="KSII Transactions on Internet and Information Systems", DOI={10.3837/tiis.2014.05.017}, volume={8}, number={5}, year="2014", month={May}, pages={1801-1816}}