Cross-Layer Analysis of Malware Datasets for Malicious Campaign Identification

Kruczkowski, M; Niewiadomska-Szynkiewicz, E; Kozakiewicz, A

  • Proceedings of the international Conference on Military Communications and Information Systems (ICMCIS);
  • Tom: -;
  • Strony: 1-7;
  • 2015;

In this paper, we investigate the problem of detecting correlations among datasets containing malicious data concerned with various types of network attacks and related events of the infections taken from a numerous sources and organizations. We propose a graph based technique to depict relationships between malicious data based on values of attributes related both to attackers and victims, and referred to different layers of the OSI model. The presented model can be used to fast, automatic identification of malware campaigns. The case study described in the paper demonstrates the performance of our method.