RADAR: A TTP-based Extensible, Explainable, and Effective System for Network Traffic Analysis and Malware Detection
Yashovardhan Sharma, Simon Birnbach, Ivan Martinovic

TL;DR
RADAR is an innovative system for network traffic analysis that leverages TTP ontology for malware detection, offering extensibility and explainability while maintaining detection performance comparable to state-of-the-art methods.
Contribution
RADAR introduces the first TTP-based, machine learning malware detection system that is both extensible and explainable, addressing key limitations of existing black-box approaches.
Findings
Effective detection on large dataset of over 2 million samples
Comparable malware detection performance to state-of-the-art systems
First TTP-based system combining extensibility, explainability, and machine learning
Abstract
Network analysis and machine learning techniques have been widely applied for building malware detection systems. Though these systems attain impressive results, they often are not extensible, being monolithic, well tuned for the specific task they have been designed for but very difficult to adapt and/or extend to other settings, and not interpretable, being black boxes whose inner complexity makes it impossible to link the result of detection with its root cause, making further analysis of threats a challenge. In this paper we present RADAR, an extensible and explainable system that exploits the popular TTP (Tactics, Techniques, and Procedures) ontology of adversary behaviour described in the industry-standard MITRE ATT\&CK framework in order to unequivocally identify and classify malicious behaviour using network traffic. We evaluate RADAR on a very large dataset…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · Advanced Malware Detection Techniques · Anomaly Detection Techniques and Applications
