Detection of malicious Encrypted Web Traffic using Machine Learning

dc.contributor.authorShah, Jay
dc.contributor.supervisorBaniasadi, Amirali
dc.contributor.supervisorTraore, Issa
dc.date.accessioned2018-11-16T03:36:49Z
dc.date.available2018-11-16T03:36:49Z
dc.date.copyright2018en_US
dc.date.issued2018-11-15
dc.degree.departmentDepartment of Electrical and Computer Engineeringen_US
dc.degree.levelMaster of Engineering M.Eng.en_US
dc.description.abstractAn increasing amount of web traffic is currently encrypted using HTTPS. While most of the HTTPS traffic is legitimate, a growing slice is generated by malware. The use of the HTTPS protocol by malware makes its detection more challenging. The current approach is to detect HTTPS malware traffic by using HTTPS interceptor proxies. This method requires decrypting the traffic on the fly, which poses some threat to the data and communication security and privacy. The goal of this project is to detect HTTPS malicious traffic without decryption. We propose a new detection model that leverages the underlying HTTPS certificate characteristics and connection data that are fed to a machine learning classifier. Our model consists of a set of features extracted from log files generated from the Bro Intrusion Detection System (IDS), which are classified using the XGBoost algorithm. Experimental evaluation is conducted using a public dataset, yielding encouraging results.en_US
dc.description.scholarlevelGraduateen_US
dc.identifier.urihttp://hdl.handle.net/1828/10313
dc.language.isoenen_US
dc.rightsAvailable to the World Wide Weben_US
dc.titleDetection of malicious Encrypted Web Traffic using Machine Learningen_US
dc.typeProjecten_US

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Shah_Jay_MEng_2018.pdf
Size:
744.02 KB
Format:
Adobe Portable Document Format
Description:
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: