Skip to main navigation Skip to search Skip to main content

A Network Behavior Analysis Method to Detect Reverse Remote Access Trojan

  • Hongyu Zhu
  • , Zhexiang Wu
  • , Jianwei Tian
  • , Zheng Tian
  • , Hong Qiao
  • , Xi Li
  • , Shengshen Chen
  • State Grid Corporation of China

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

5 Scopus citations

Abstract

Remote Access Trojan (RAT)reverse connections are secret and malicious, which are established to steal private data or be operated under hacker's command. To detect reverse RAT effectively, a network behavior-based method is introduced in this paper. We first conclude a typical network communication pattern. Then four uncorrelated network behavior features are extracted from every TCP session as the detection model input. Six supervised classification algorithms are applied on real network traffic data set to distinguish RAT and legitimate sessions. Besides detection accuracy, AUC is also used because the amount of RAT sessions is much less than normal sessions and AUC is suitable to evaluate the performance of such imbalanced problem. Detection accuracies of all test algorithms are higher than 0.92. AUC of Random Forest, SVM and Logistic Regression are higher than 0.94, which shows their ability to handle imbalanced data set. Compared to related work, the proposed method is effective on connection encrypted RAT detection, and can distinguish RAT sessions from similar normal sessions, like P2P or cloud application sessions.

Original languageEnglish
Title of host publicationICSESS 2018 - Proceedings of 2018 IEEE 9th International Conference on Software Engineering and Service Science
EditorsLi Wenzheng, M. Surendra Prasad Babu
PublisherIEEE Computer Society
Pages1007-1010
Number of pages4
ISBN (Electronic)9781538665640
DOIs
StatePublished - 2 Jul 2018
Externally publishedYes
Event9th IEEE International Conference on Software Engineering and Service Science, ICSESS 2018 - Beijing, China
Duration: 23 Nov 201825 Nov 2018

Publication series

NameProceedings of the IEEE International Conference on Software Engineering and Service Sciences, ICSESS
Volume2018-November
ISSN (Print)2327-0586
ISSN (Electronic)2327-0594

Conference

Conference9th IEEE International Conference on Software Engineering and Service Science, ICSESS 2018
Country/TerritoryChina
CityBeijing
Period23/11/1825/11/18

Keywords

  • Machine learning
  • Network Security
  • Network behavior
  • Trojan Detection

Fingerprint

Dive into the research topics of 'A Network Behavior Analysis Method to Detect Reverse Remote Access Trojan'. Together they form a unique fingerprint.

Cite this