Talk With an Expert

60 Seconds on the Wire: A Look at Malicious Traffic

60 Seconds on the Wire: A Look at Malicious Traffic (PDF, 3.87MB)Published: 19 Aug, 2013
Created by
Kiel Wadner

Despite advances in detection, malware remains an active and high-risk threat to organizations. Understanding the characteristics of malware traffic can be vital in detecting, as well as responding to an incident inside an organization. In this paper, over 20,000 PCAPS generated by known malware are explored to find these characteristics. The focus of the research is on HTTP traffic since this was the predominate communication protocol seen. Based on the findings, suggestions are offered towards effective detection of malware traffic. As it will be shown, despite attempts to hide or obfuscate itself, malicious traffic was detected with a high level of success.

60 Seconds on the Wire: A Look at Malicious Traffic