Volume 4 Number 6 (Nov. 2015)
Home > Archive > 2015 > Volume 4 Number 6 (Nov. 2015) >
IJCCE 2015 Vol.4(6): 379-389 ISSN: 2010-3743
DOI: 10.17706/IJCCE.2015.4.6.379-389

In-Host Communication Pattern Observed for Suspicious HTTP-Based Auto-Ware Detection

Manh Cong Tran, Yasuhiro Nakamura
Abstract—In consequence of the growing cyber security threats, normal users and also system administrators are advised to closing inward ports and permitting outgoing communication only over selected protocols. In many decades, the flexibility and interoperability of HTTP make users progressively explore it in a much wider range of applications. Therefore, HTTP is always allowed on the network perimeter. HTTP-based applications could be classified into two types of Internet accesses: passive and active HTTP access applications. Passive type application (i.e. browsers) has just generated requests on users’ demands, so users can clarify and control what content they will access and accomplish. On the contrary, active type is called automatic software (auto-ware), which allows completely or partly automatically access to its servers without users’ intention. Auto-ware could be normal applications such as virus defining or operating system updating, but also are abnormal processes such as botnet, worms, virus, spywares, and advertising software (adware). Therefore, auto-ware, in a sense, consumes network bandwidth, and it might become internal security threats. Detection of suspicious auto-ware and its traffics are challenge work because the malicious traffic merges sufficiently with legitimate HTTP traffic. In this paper, based on the observation of communication pattern of HTTP auto-ware, it is proposed a detection method of HTTP-based Auto-ware. The experiment results show that the method is useful for host-based detection application.

Index Terms—HTTP-based malware, malware detection, network security management, periodic communication.

The authors are with the Department of Computer Science, National Defense Academy, Yokosuka 239-0811, Japan.

Cite:Manh Cong Tran, Yasuhiro Nakamura, "In-Host Communication Pattern Observed for Suspicious HTTP-Based Auto-Ware Detection," International Journal of Computer and Communication Engineering vol. 4, no. 6, pp. 379-389, 2015.

General Information

ISSN: 2010-3743 (Online)
Abbreviated Title: Int. J. Comput. Commun. Eng.
Frequency: Quarterly
Editor-in-Chief: Dr. Maode Ma
Abstracting/ Indexing: INSPEC, CNKI, Google Scholar, Crossref, EBSCO, ProQuest, and Electronic Journals Library
E-mail: ijcce@iap.org
  • Dec 29, 2021 News!

    IJCCE Vol. 10, No. 1 - Vol. 10, No. 2 have been indexed by Inspec, created by the Institution of Engineering and Tech.!   [Click]

  • Mar 17, 2022 News!

    IJCCE Vol.11, No.2 is published with online version!   [Click]

  • Dec 29, 2021 News!

    The dois of published papers in Vol. 9, No. 3 - Vol. 10, No. 4 have been validated by Crossref.

  • Dec 29, 2021 News!

    IJCCE Vol.11, No.1 is published with online version!   [Click]

  • Sep 16, 2021 News!

    IJCCE Vol.10, No.4 is published with online version!   [Click]

  • Read more>>