Malware Threat Affecting Financial Organization Analysis Using Machine Learning Approach
Анализ угрозы вредоносного ПО, воздействующей на финансовые организации, с использованием машинного обучения
2022-08-05
SCID: 54.1/7zdgdrkf
Discuss with AI
Emotet malwarefinancial cybersecurityman-in-the-browser attacksnetwork traffic classificationrandom forest classifier
Figures from the paper
Abstract (AI)
Since 2014, Emotet has been using man-in-the-browsers (MITB) attacks to target companies in the finance industry and their clients. Its key aim is to steal victims' online money-lending records and vital credentials as they go to their banks' websites. Without analyzing network packet payload computing (PPC), IP address labels, port number traces, or protocol knowledge, the authors have used machine learning (ML) modeling to detect Emotet malware infections and recognize Emotet-related congestion flows in this work. To classify Emotet-associated flows and detect Emotet infections, the output outcome values are compared by four separate popular ML algorithms: RF (random forest), MLP (multi-layer perceptron), SMO (sequential minimal optimization technique), and the LRM (logistic regression model). The suggested classifier is then improved by determining the right hyperparameter and attribute set range. Using network packet (computation) identifiers, the random forest classifier detects Emotet-based flows with 99.9726% precision and a 92.3% true positive rating.
Key Findings
1
A machine-learning approach detects Emotet infections and identifies Emotet-related network flows without analyzing packet payloads, IP labels, ports, or protocol knowledge.
2
Four classifiers—random forest, multilayer perceptron, sequential minimal optimization, and logistic regression—are compared for Emotet-flow classification and infection detection.
3
Hyperparameter selection and feature-set optimization improve the proposed Emotet detection classifier.
4
Using network packet computation identifiers, random forest achieves 99.9726% precision and a 92.3% true-positive rate for detecting Emotet-based flows targeting financial organizations.
Research Object
Emotet malware infections and Emotet-related network congestion flows targeting financial organizations and their clients
Research Subject
Machine-learning-based detection and classification performance for Emotet infections and associated network flows using network packet identifiers, with optimized hyperparameters and attribute sets
Publication Details
Publication Date
2022-08-05
Journal
Publisher
ISSN
Cited by
98
Open access PDF
Access Type
Author Information
Download PDF
Subscribe to digest