Vše

Co hledáte?

Vše
Projekty
Výsledky výzkumu
Subjekty

Rychlé hledání

  • Projekty podpořené TA ČR
  • Významné projekty
  • Projekty s nejvyšší státní podporou
  • Aktuálně běžící projekty

Chytré vyhledávání

  • Takto najdu konkrétní +slovo
  • Takto z výsledků -slovo zcela vynechám
  • “Takto můžu najít celou frázi”

Experience Report: Using JA4+ Fingerprints for Malware Detection in Encrypted Traffic

Identifikátory výsledku

  • Kód výsledku v IS VaVaI

    <a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F00216305%3A26230%2F26%3A0189464" target="_blank" >RIV/00216305:26230/26:0189464 - isvavai.cz</a>

  • Výsledek na webu

    <a href="https://www.fit.vut.cz/research/publication/13252/" target="_blank" >https://www.fit.vut.cz/research/publication/13252/</a>

  • DOI - Digital Object Identifier

    <a href="http://dx.doi.org/10.23919/CNSM62983.2024.10814358" target="_blank" >10.23919/CNSM62983.2024.10814358</a>

Alternativní jazyky

  • Jazyk výsledku

    angličtina

  • Název v původním jazyce

    Experience Report: Using JA4+ Fingerprints for Malware Detection in Encrypted Traffic

  • Popis výsledku v původním jazyce

    Detection of malware communications is limited due to encryption. Malware control, updates, and distribution are encapsulated in TLS tunnels, making it difficult to distinguish between malicious and benign transmissions. One way, how to detect malware communication, is to analyze the TLS handshake and obtain so-called JA4+ fingerprints. This report analyses the effectiveness of JA4+ fingerprints for malware detection, focusing specifically on the JA4, JA4S and JA4X fingerprints and their accuracy. It examines the process of creating malware fingerprints, explores the uniqueness of these fingerprints across&nbsp; different malware families and their ability to distinguish between malicious and benign applications. By examining the overlap and uniqueness, the study evaluates the effectiveness of using JA4+ fingerprints to detect malware in encrypted communications.

  • Název v anglickém jazyce

    Experience Report: Using JA4+ Fingerprints for Malware Detection in Encrypted Traffic

  • Popis výsledku anglicky

    Detection of malware communications is limited due to encryption. Malware control, updates, and distribution are encapsulated in TLS tunnels, making it difficult to distinguish between malicious and benign transmissions. One way, how to detect malware communication, is to analyze the TLS handshake and obtain so-called JA4+ fingerprints. This report analyses the effectiveness of JA4+ fingerprints for malware detection, focusing specifically on the JA4, JA4S and JA4X fingerprints and their accuracy. It examines the process of creating malware fingerprints, explores the uniqueness of these fingerprints across&nbsp; different malware families and their ability to distinguish between malicious and benign applications. By examining the overlap and uniqueness, the study evaluates the effectiveness of using JA4+ fingerprints to detect malware in encrypted communications.

Klasifikace

  • Druh

    D - Stať ve sborníku

  • CEP obor

  • OECD FORD obor

    10201 - Computer sciences, information science, bioinformathics (hardware development to be 2.2, social aspect to be 5.8)

Návaznosti výsledku

  • Projekt

    <a href="/cs/project/VJ02010024" target="_blank" >VJ02010024: Analýza šifrovaného provozu pomocí síťových toků</a><br>

  • Návaznosti

    P - Projekt vyzkumu a vyvoje financovany z verejnych zdroju (s odkazem do CEP)<br>S - Specificky vyzkum na vysokych skolach

Ostatní

  • Rok uplatnění

    2024

  • Kód důvěrnosti údajů

    S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů

Údaje specifické pro druh výsledku

  • Název statě ve sborníku

    Proceedings of 20th International Conference on Network and Service Management

  • ISBN

    979-8-3315-0515-8

  • ISSN

  • e-ISSN

  • Počet stran výsledku

    5

  • Strana od-do

    1-5

  • Název nakladatele

    Institute of Electrical and Electronics Engineers

  • Místo vydání

    Prague

  • Místo konání akce

    Praha

  • Datum konání akce

    28. 10. 2024

  • Typ akce podle státní příslušnosti

    WRD - Celosvětová akce

  • Kód UT WoS článku

    001414325200019