Exposing the Rat in the Tunnel: Using Traffic Analysis for Tor-based Malware Detection
Priyanka Dodia, Mashael AlSabah, Omar Alrawi, Tao Wang
摘要
Tor [31] is the most widely used anonymous communication network with millions of daily users [6]. Since Tor provides server and client anonymity, hundreds of malware binaries found in the wild rely on it to hide their presence and hinder Command & Control (C&C) takedown operations. We believe Tor is a paramount tool enabling online freedom and privacy, and blocking it to defend against such malware is infeasible for both users and organizations. In this work, we present effective traffic analysis approaches that can accurately identify Tor-based malware communication. We collect hundreds of Tor-based malware binaries, execute and examine more than 47,000 active encrypted malware connections and compare them with benign browsing traffic. In addition to traditional traffic analysis features (which work at the connection level), we propose global host-level network features to capture peculiar malware communication fingerprints across host logs. Our experiments confirm that our models are able to detect "zero-day" malware connections with 0.7% FPR even when malware connections constitute less than 5% of Tor traces in the test set. Using multi-labeling approaches, we are able to accurately detect the malware behavior-based classes (grayware, ransomware, etc). Finally, we evaluate the robustness of our models on real-world enterprise logs and show that the classifiers can identify infected hosts even with missing features. CCS CONCEPTS • Security and privacy → Malware and its mitigation; Privacypreserving protocols.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper11
- Point Cloud Analysis for ML-Based Malicious Traffic Detection: Reducing Majorities of False Positive AlarmsChuanpu Fu, Qi Li, Ke Xu, Jianping WuCCS 2023 · 被引用 30 次
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren 等CCS 2023 · 被引用 19 次
- Detecting Tunneled Flooding Traffic via Deep Semantic Analysis of Packet Length PatternsChuanpu Fu, Qi Li, Meng Shen, Ke XuCCS 2024 · 被引用 13 次
- In Search of netUnicorn: A Data-Collection Platform to Develop Generalizable ML Models for Network Security ProblemsRoman Beltiukov, Wenbo Guo, Arpit Gupta, Walter WillingerCCS 2023 · 被引用 10 次
- A Hard-Label Black-Box Evasion Attack against ML-based Malicious Traffic Detection SystemsZixuan Liu, Yi Zhao, Zhuotao Liu, Qi Li 等NDSS 2026 · 被引用 3 次
它引用的顶会 Paper6
- Deep Fingerprinting: Undermining Website Fingerprinting Defenses with Deep LearningPayap Sirinam, Mohsen Imani, Marc Juarez, Matthew WrightCCS 2018 · 被引用 632 次
- Triplet Fingerprinting: More Practical and Portable Website Fingerprinting with N-shot LearningPayap Sirinam, Nate Mathews, Mohammad Saidur Rahman, Matthew WrightCCS 2019 · 被引用 268 次
- Beauty and the Burst: Remote Identification of Encrypted Video StreamsRoei Schuster, Vitaly Shmatikov, Eran TromerUSENIX Security 2017 · 被引用 205 次
- The Circle Of Life: A Large-Scale Study of The IoT Malware LifecycleOmar Alrawi, Charles Lever, Kevin Valakuzhy, Ryan Court 等USENIX Security 2021 · 被引用 109 次
- Forecasting Malware Capabilities From Cyber Attack Memory ImagesOmar Alrawi, Moses Ike, Matthew Pruett, Ranjita Pai Kasturi 等USENIX Security 2021 · 被引用 32 次
相关 Paper
- Fingerprinting the Shadows: Unmasking Malicious Servers with Machine Learning-Powered TLS AnalysisAndreas Theofanous, Eva Papadogiannaki, Alexander Shevtsov, Sotiris IoannidisWWW 2024 · 被引用 7 次
- Transformer-based Model for Multi-tab Website Fingerprinting AttackZhaoxin Jin, Tianbo Lu, Shuang Luo, Jiaze ShangCCS 2023 · 被引用 30 次
- Large-scale Evaluation of Malicious Tor Hidden Service Directory DiscoveryChunmian Wang, Zhen Ling, Wenjia Wu, Qi Chen 等INFOCOM 2022 · 被引用 10 次
- Subverting Website Fingerprinting Defenses with Robust Traffic RepresentationMeng Shen, Kexin Ji, Zhenbo Gao, Qi Li 等USENIX Security 2023
- Do Not Trust What They Tell: Exposing Malicious Accomplices in Tor via Anomalous Circuit DetectionYixuan Yao, Ming Yang, Zixia Liu, Kai Dong 等WWW 2025 · 被引用 2 次
