Time Pattern Analysis of Malware by Circular Statistics
Title | Time Pattern Analysis of Malware by Circular Statistics |
Publication Type | Conference Paper |
Year of Publication | 2017 |
Authors | Pan, Liuxuan, Tomlinson, Allan, Koloydenko, Alexey A. |
Conference Name | Proceedings of the Symposium on Architectures for Networking and Communications Systems |
Publisher | IEEE Press |
Conference Location | Piscataway, NJ, USA |
ISBN Number | 978-1-5090-6386-4 |
Keywords | Circular statistics, Human Behavior, human factors, Malware, Metrics, pubcrawl, Resiliency, Scalability, Security Risk Estimation, time patterns, uniformity hypothesis test |
Abstract | Circular statistics present a new technique to analyse the time patterns of events in the field of cyber security. We apply this technique to analyse incidents of malware infections detected by network monitoring. In particular we are interested in the daily and weekly variations of these events. Based on "live" data provided by Spamhaus, we examine the hypothesis that attacks on four countries are distributed uniformly over 24 hours. Specifically, we use Rayleigh and Watson tests. While our results are mainly exploratory, we are able to demonstrate that the attacks are not uniformly distributed, nor do they follow a Poisson distribution as reported in other research. Our objective in this is to identify a distribution that can be used to establish risk metrics. Moreover, our approach provides a visual overview of the time patterns' variation, indicating when attacks are most likely. This will assist decision makers in cyber security to allocate resources or estimate the cost of system monitoring during high risk periods. Our results also reveal that the time patterns are influenced by the total number of attacks. Networks subject to a large volume of attacks exhibit bimodality while one case, where attacks were at relatively lower rate, showed a multi-modal daily variation. |
URL | http://ieeexplore.ieee.org/document/7966911/ |
DOI | 10.1109/ANCS.2017.26 |
Citation Key | pan_time_2017 |