[ << ALL_FEED ]

Dissecting network traffic with ML in search of new malware

More in Phishing & sandbox

Dissecting network traffic with ML in search of new malware 📖

🧪 We — the network expertise department team of the ESC antivirus laboratory and the machine learning team — once built an ML model on network traffic, trained it on real network sessions, and launched it in the PT Sandbox sandbox to enhance malware detection capabilities. But we decided not to rest on our laurels — we conducted a series of new experiments, expanded the set of input features, and tested the model on more complex scenarios.

👾 Thanks to the update, the model has already managed to catch several previously unknown samples: a new version of the Oyster backdoor, the APT GOFFEE loader, several stealers (for example, JustAskJacky), and a number of other small but suspicious loaders.

💡 This experience confirms that machine learning is an excellent assistant to traditional signature-based solutions: it sees hidden patterns and increases the overall detectability of malicious network scenarios.

We talked about all this and more in our article on Habr.

#network #avlab #ml
@ptescalator

More from global_author

More from global_author

More in Phishing & sandbox