Scholay

学术搜索 · AI 审稿 · LaTeX 协作

MalTAG: Encrypted Malware Traffic Detection Framework via Graph Based Flow Interaction Mining

作者:Renjie Li, Zhou Zhou, Miao Hao, Fengyuan Shi, Qingyun Liu · 年份:2025 · DOI:10.1109/dsn64029.2025.00052 · 被引用次数:1 · 研究领域:Network Security and Intrusion Detection、Internet Traffic Analysis and Secure E-voting、Advanced Malware Detection Techniques

As encrypted malware campaigns become more sophisticated, significant challenges arise in effectively detecting malicious communications when relying solely on single-stream or single-feature network traffic analysis methods. Therefore, we propose MalTAG, a graph-based flow interaction mining framework to address existing challenges. MalTAG integrates network traffic into a multi-flow correlated graph and incorpo-rates various feature types rather than relying on a single stream or single type of feature. It effectively captures the contextual correlation properties of malicious activities in both temporal and attribute dimensions. Furthermore, MalTAG achieves graph representation learning through self-supervised contrastive learning without relying on prior label knowledge. This design helps to construct more stable representations of traffic behavior to adapt to the evolving nature of malicious activities. Ultimately, it utilizes various machine learning algorithms to detect malicious traffic comprehensively. Experimental evaluations demonstrate the feasibility and good performance of MalTAG in malware detection and family classification, outperforming existing methods.