Pith. sign in

REVIEW 1 cited by

Feature Analysis of Encrypted Malicious Traffic

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2312.04596 v1 pith:SHKGJSFI submitted 2023-12-06 cs.CR cs.LG

classification cs.CRcs.LG
keywords encryptedtrafficanalysismaliciousfeaturelearningmachineprevious
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

In recent years there has been a dramatic increase in the number of malware attacks that use encrypted HTTP traffic for self-propagation or communication. Antivirus software and firewalls typically will not have access to encryption keys, and therefore direct detection of malicious encrypted data is unlikely to succeed. However, previous work has shown that traffic analysis can provide indications of malicious intent, even in cases where the underlying data remains encrypted. In this paper, we apply three machine learning techniques to the problem of distinguishing malicious encrypted HTTP traffic from benign encrypted traffic and obtain results comparable to previous work. We then consider the problem of feature analysis in some detail. Previous work has often relied on human expertise to determine the most useful and informative features in this problem domain. We demonstrate that such feature-related information can be obtained directly from machine learning models themselves. We argue that such a machine learning based approach to feature analysis is preferable, as it is more reliable, and we can, for example, uncover relatively unintuitive interactions between features.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Integrating Explainable AI for Effective Malware Detection in Encrypted Network Traffic

    cs.CR 2025-01 reject novelty 3.0 of 10

    An application of standard ensemble classifiers and SHAP to a private dataset reports >99% detection accuracy, but the evaluation may be leaky and no baselines are given.

Pith tools