APT MALWARE DETECTION ON COMPUTER NETWORK WITH MACHINE LEARNING TECHNIQUE

In the world of technology, malware or malicious software is often used for cybercrime activities (e.g., stealing credential information, spying on someone, etc.). Some criminal organizations try to use malware as a facility for achieving their goal. Malware is often used in one type of cyber-attack...

Full description

Saved in:
Bibliographic Details
Main Author: Pratama, Aditya
Format: Final Project
Language:Indonesia
Online Access:https://digilib.itb.ac.id/gdl/view/42510
Tags: Add Tag
No Tags, Be the first to tag this record!
Institution: Institut Teknologi Bandung
Language: Indonesia
id id-itb.:42510
spelling id-itb.:425102019-09-20T10:29:18ZAPT MALWARE DETECTION ON COMPUTER NETWORK WITH MACHINE LEARNING TECHNIQUE Pratama, Aditya Indonesia Final Project malware, APT, characteristics, malware detection technique , machine learning. INSTITUT TEKNOLOGI BANDUNG https://digilib.itb.ac.id/gdl/view/42510 In the world of technology, malware or malicious software is often used for cybercrime activities (e.g., stealing credential information, spying on someone, etc.). Some criminal organizations try to use malware as a facility for achieving their goal. Malware is often used in one type of cyber-attack by organization called APT or Advanced Persistent Threat. In short, APT attack is a sophisticated cyberattack that designed by an organization. Organization that carry out APT attack generally have good resources, organized, and have specific targets such as government, well-known companies, etc. Until now, malware detection tools on network such as Snort and Suricata have not been able to detect APT malware activity effectively due to special characteristics of APT malware and using signature-based malware detection technique to detect APT malware activity. Therefore, this study will build a malware detection system that can handle the characteristics of APT malware and can detect APT malware activity on network using non-signature based approach. This study begins by analyzing all matters related to APT attacks, starting from the definition, characteristics, and the attack process. Then, things that cause the ineffectiveness of malware detection tools when detecting APT malware will be sought and analyzed. From those causes, the most appropriate malware detection technique will be sought. After that, the proposed system will be built using the most appropriate technique and engine based on machine learning. The engine on system will be built using machine learning technique because all malware detection techniques beside signature-based are using machine learning to build its engine. In the end, the proposed system can detect APT malware activity on network from 36 pcap file that contain APT malware activity with recall 57.895% - 100%, and false negative 8% - 31% on benign network. text
institution Institut Teknologi Bandung
building Institut Teknologi Bandung Library
continent Asia
country Indonesia
Indonesia
content_provider Institut Teknologi Bandung
collection Digital ITB
language Indonesia
description In the world of technology, malware or malicious software is often used for cybercrime activities (e.g., stealing credential information, spying on someone, etc.). Some criminal organizations try to use malware as a facility for achieving their goal. Malware is often used in one type of cyber-attack by organization called APT or Advanced Persistent Threat. In short, APT attack is a sophisticated cyberattack that designed by an organization. Organization that carry out APT attack generally have good resources, organized, and have specific targets such as government, well-known companies, etc. Until now, malware detection tools on network such as Snort and Suricata have not been able to detect APT malware activity effectively due to special characteristics of APT malware and using signature-based malware detection technique to detect APT malware activity. Therefore, this study will build a malware detection system that can handle the characteristics of APT malware and can detect APT malware activity on network using non-signature based approach. This study begins by analyzing all matters related to APT attacks, starting from the definition, characteristics, and the attack process. Then, things that cause the ineffectiveness of malware detection tools when detecting APT malware will be sought and analyzed. From those causes, the most appropriate malware detection technique will be sought. After that, the proposed system will be built using the most appropriate technique and engine based on machine learning. The engine on system will be built using machine learning technique because all malware detection techniques beside signature-based are using machine learning to build its engine. In the end, the proposed system can detect APT malware activity on network from 36 pcap file that contain APT malware activity with recall 57.895% - 100%, and false negative 8% - 31% on benign network.
format Final Project
author Pratama, Aditya
spellingShingle Pratama, Aditya
APT MALWARE DETECTION ON COMPUTER NETWORK WITH MACHINE LEARNING TECHNIQUE
author_facet Pratama, Aditya
author_sort Pratama, Aditya
title APT MALWARE DETECTION ON COMPUTER NETWORK WITH MACHINE LEARNING TECHNIQUE
title_short APT MALWARE DETECTION ON COMPUTER NETWORK WITH MACHINE LEARNING TECHNIQUE
title_full APT MALWARE DETECTION ON COMPUTER NETWORK WITH MACHINE LEARNING TECHNIQUE
title_fullStr APT MALWARE DETECTION ON COMPUTER NETWORK WITH MACHINE LEARNING TECHNIQUE
title_full_unstemmed APT MALWARE DETECTION ON COMPUTER NETWORK WITH MACHINE LEARNING TECHNIQUE
title_sort apt malware detection on computer network with machine learning technique
url https://digilib.itb.ac.id/gdl/view/42510
_version_ 1821998626503655424