Detecting random filenames using (un)supervised machine learning
Summary
For instance, we develop machine learning techniques for detecting malicious content such as DGA domains or unusual SMB traffic. During traffic analysis of lateral movement we sometimes recognize random filenames, indicating possible malicious activity or content. In this blogpost we build on our previous blog entry [2] and we describe how we can apply the magic of machine learning in detection of random filenames in SMB traffic. It is possible that the bigrams model requires more data to create it’s baseline and therefore doesn’t perform as well as the supervised random forest. During traffic analysis in our Security Operations Center we sometimes recognize random filenames, indicating possible lateral movement.
Classifications
industries
Fintech & Banking
applications
Web and Content Management
AskAI Classifications
Labels
No AI classifications detected