Publications (4)
MBTree: Detecting Encryption RAT Communication Using Malicious Behavior Tree
Cong Dong, Zhigang Lu, Zelin Cui +2
Network trace signature matching is one reliable approach to detect active Remote Control Trojan, (RAT). Compared to statistical-based detection of malicious network traces in the…
ProvAgent: Threat Detection Based on Identity-Behavior Binding and Multi-Agent Collaborative Attack Investigation
Wenhao Yan, Ning An, Linxu Li +6
Advanced Persistent Threats (APTs) pose critical challenges to modern cybersecurity due to their multi-stage and stealthy nature. While provenance-based detection approaches show p…
E-DoH: Elegantly Detecting the Depths of Open DoH Service on the Internet
Cong Dong, Jiahai Yang, Yun Li +6
In recent years, DNS over Encrypted (DoE) methods have been regarded as a novel trend within the realm of the DNS ecosystem. In these DoE methods, DNS over HTTPS (DoH) provides enc…
CBSeq: A Channel-level Behavior Sequence For Encrypted Malware Traffic Detection
Susu Cui, Cong Dong, Meng Shen +3
Machine learning and neural networks have become increasingly popular solutions for encrypted malware traffic detection. They mine and learn complex traffic patterns, enabling dete…