Malware Threat Affecting Financial Organization Analysis Using Machine Learning Approach

Анализ угрозы вредоносного ПО, воздействующей на финансовые организации, с использованием машинного обучения
Romil Rawat, Sanjaya Kumar Sarangi, Yagyanath Rimal, P. William, Snehil Dahima, Sonali Gupta, K. Sakthidasan Sankaran
2022-08-05

Emotet malwarefinancial cybersecurityman-in-the-browser attacksnetwork traffic classificationrandom forest classifier
Since 2014, Emotet has been using man-in-the-browsers (MITB) attacks to target companies in the finance industry and their clients. Its key aim is to steal victims' online money-lending records and vital credentials as they go to their banks' websites. Without analyzing network packet payload computing (PPC), IP address labels, port number traces, or protocol knowledge, the authors have used machine learning (ML) modeling to detect Emotet malware infections and recognize Emotet-related congestion flows in this work. To classify Emotet-associated flows and detect Emotet infections, the output outcome values are compared by four separate popular ML algorithms: RF (random forest), MLP (multi-layer perceptron), SMO (sequential minimal optimization technique), and the LRM (logistic regression model). The suggested classifier is then improved by determining the right hyperparameter and attribute set range. Using network packet (computation) identifiers, the random forest classifier detects Emotet-based flows with 99.9726% precision and a 92.3% true positive rating.
1
A machine-learning approach detects Emotet infections and identifies Emotet-related network flows without analyzing packet payloads, IP labels, ports, or protocol knowledge.
2
Four classifiers—random forest, multilayer perceptron, sequential minimal optimization, and logistic regression—are compared for Emotet-flow classification and infection detection.
3
Hyperparameter selection and feature-set optimization improve the proposed Emotet detection classifier.
4
Using network packet computation identifiers, random forest achieves 99.9726% precision and a 92.3% true-positive rate for detecting Emotet-based flows targeting financial organizations.

Emotet malware infections and Emotet-related network congestion flows targeting financial organizations and their clients

Machine-learning-based detection and classification performance for Emotet infections and associated network flows using network packet identifiers, with optimized hyperparameters and attribute sets

Publication Details
Publication Date
2022-08-05
Journal
Publisher
ISSN
Cited by
98
Access Type
Author Information
Authors
Romil Rawat
Sanjaya Kumar Sarangi
Yagyanath Rimal
P. William
Snehil Dahima
Sonali Gupta
K. Sakthidasan Sankaran
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%