{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,9]],"date-time":"2026-04-09T14:36:14Z","timestamp":1775745374857,"version":"3.50.1"},"reference-count":22,"publisher":"MDPI AG","issue":"5","license":[{"start":{"date-parts":[[2021,4,23]],"date-time":"2021-04-23T00:00:00Z","timestamp":1619136000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Entropy"],"abstract":"<jats:p>Malicious software utilizes HTTP protocol for communication purposes, creating network traffic that is hard to identify as it blends into the traffic generated by benign applications. To this aim, fingerprinting tools have been developed to help track and identify such traffic by providing a short representation of malicious HTTP requests. However, currently existing tools do not analyze all information included in the HTTP message or analyze it insufficiently. To address these issues, we propose Hfinger, a novel malware HTTP request fingerprinting tool. It extracts information from the parts of the request such as URI, protocol information, headers, and payload, providing a concise request representation that preserves the extracted information in a form interpretable by a human analyst. For the developed solution, we have performed an extensive experimental evaluation using real-world data sets and we also compared Hfinger with the most related and popular existing tools such as FATT, Mercury, and p0f. The conducted effectiveness analysis reveals that on average only 1.85% of requests fingerprinted by Hfinger collide between malware families, what is 8\u201334 times lower than existing tools. Moreover, unlike these tools, in default mode, Hfinger does not introduce collisions between malware and benign applications and achieves it by increasing the number of fingerprints by at most 3 times. As a result, Hfinger can effectively track and hunt malware by providing more unique fingerprints than other standard tools.<\/jats:p>","DOI":"10.3390\/e23050507","type":"journal-article","created":{"date-parts":[[2021,4,23]],"date-time":"2021-04-23T12:08:30Z","timestamp":1619179710000},"page":"507","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":7,"title":["Hfinger: Malware HTTP Request Fingerprinting"],"prefix":"10.3390","volume":"23","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4077-5885","authenticated-orcid":false,"given":"Piotr","family":"Bia\u0142czak","sequence":"first","affiliation":[{"name":"CERT Polska\/Research and Academic Computer Network (NASK), Kolska 12, 01-045 Warsaw, Poland"},{"name":"Institute of Computer Science, Warsaw University of Technology, Nowowiejska 15\/19, 00-665 Warsaw, Poland"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8509-4127","authenticated-orcid":false,"given":"Wojciech","family":"Mazurczyk","sequence":"additional","affiliation":[{"name":"Institute of Computer Science, Warsaw University of Technology, Nowowiejska 15\/19, 00-665 Warsaw, Poland"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2021,4,23]]},"reference":[{"key":"ref_1","unstructured":"Miller, S., and Smith, P. (2017). Rise of Legitimate Services for Backdoor Command and Control, Anomali. Available online: https:\/\/www.anomali.com\/files\/anomali-labs-reports\/legit-services.pdf."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Capocelli, R., De Santis, A., and Vaccaro, U. (1993). Some applications of Rabin\u2019s fingerprinting method. Sequences II, Springer.","DOI":"10.1007\/978-1-4613-9323-8"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Li, K., Chen, R., Gu, L., Liu, C., and Yin, J. (2018, January 18\u201321). A Method Based on Statistical Characteristics for Detection Malware Requests in Network Traffic. Proceedings of the 2018 IEEE Third International Conference on Data Science in Cyberspace (DSC), Guangzhou, China.","DOI":"10.1109\/DSC.2018.00084"},{"key":"ref_4","unstructured":"Perdisci, R., Lee, W., and Feamster, N. (2010, January 28\u201330). Behavioral Clustering of HTTP-Based Malware and Signature Generation Using Malicious Network Traces. Proceedings of the NSDI \u201910: 7th USENIX Symposium on Networked Systems Design and Implementation, San Jose, CA, USA."},{"key":"ref_5","unstructured":"GmbH, A.T. (2020). AV-TEST Security Report 2019\/2020, AV-TEST Institute. Available online: https:\/\/www.av-test.org\/fileadmin\/pdf\/security_report\/AV-TEST_Security_Report_2019-2020.pdf."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Laperdrix, P., Bielova, N., Baudry, B., and Avoine, G. (2019). Browser Fingerprinting: A survey. arXiv.","DOI":"10.1145\/3386040"},{"key":"ref_7","unstructured":"Bortolameotti, R., van Ede, T., Caselli, M., Everts, M.H., Hartel, P., Hofstede, R., Jonker, W., and Peter, A. (2017, January 4\u20138). DECANTeR: DEteCtion of Anomalous OutbouNd HTTP TRaffic by Passive Application Fingerprinting. Proceedings of the 33rd Annual Computer Security Applications Conference (ACSAC 2017), Orlando, FL, USA."},{"key":"ref_8","unstructured":"Bortolameotti, R., van Ede, T., Continella, A., Hupperich, T., Everts, M.H., Rafati, R., Jonker, W., Hartel, P., and Peter, A. (April, January 30). HeadPrint: Detecting Anomalous Communications through Header-Based Application Fingerprinting. Proceedings of the 35th Annual ACM Symposium on Applied Computing (SAC \u201920), Brno, Czech Republic."},{"key":"ref_9","unstructured":"Shbair, W.M., Cholez, T., Francois, J., and Chrisment, I. (2020). A Survey of HTTPS Traffic and Services Identification Approaches. arXiv."},{"key":"ref_10","unstructured":"Stringhini, G., Egele, M., Zarras, A., Holz, T., Kruegel, C., and Vigna, G. (2012, January 8\u201310). B@bel: Leveraging Email Delivery for Spam Mitigation. Proceedings of the 21st USENIX Security Symposium (USENIX Security 12), Bellevue, WA, USA."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"25","DOI":"10.1109\/MSP.2017.4251116","article-title":"Botnet Fingerprinting: Anomaly Detection in SMTP Conversations","volume":"15","author":"Lasota","year":"2017","journal-title":"IEEE Secur. Priv."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Fachkha, C., Bou-Harb, E., and Debbabi, M. (April, January 30). Fingerprinting Internet DNS Amplification DDoS Activities. Proceedings of the 2014 6th International Conference on New Technologies, Mobility and Security (NTMS), Dubai, United Arab Emirates.","DOI":"10.1109\/NTMS.2014.6814019"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Kim, T., and Ju, H. (2011, January 21\u201323). Effective DNS server fingerprinting method. Proceedings of the 2011 13th Asia-Pacific Network Operations and Management Symposium, Taipei, Taiwan.","DOI":"10.1109\/APNOMS.2011.6076955"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"1701","DOI":"10.1109\/TNSM.2020.2996502","article-title":"Botnet Fingerprinting: A Frequency Distributions Scheme for Lightweight Bot Detection","volume":"17","author":"Blaise","year":"2020","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"ref_15","unstructured":"Ory, S., Aharon, F., and Elad, S. (2017). Passive Fingerprinting of HTTP\/2 Clients, Akamai. Technical Report."},{"key":"ref_16","unstructured":"Holland, J., Schmitt, P., Feamster, N., and Mittal, P. (2020). nPrint: Standard Packet-level Network Traffic Analysis. arXiv."},{"key":"ref_17","first-page":"8848863","article-title":"Characterizing Anomalies in Malware-Generated HTTP Traffic","volume":"2020","author":"Mazurczyk","year":"2020","journal-title":"Secur. Commun. Netw."},{"key":"ref_18","unstructured":"Sahoo, D., Liu, C., and Hoi, S.C.H. (2019). Malicious URL Detection using Machine Learning: A Survey. arXiv."},{"key":"ref_19","unstructured":"Fowler, G., Noll, L.C., Vo, K.P., Eastlake, D., and Hansen, T. (2020, July 27). The FNV Non-Cryptographic Hash Algorithm. Available online: https:\/\/tools.ietf.org\/html\/draft-eastlake-fnv."},{"key":"ref_20","unstructured":"(2020, July 27). Windows 10 Has an Undocumented Certificate Pinning Feature. Available online: https:\/\/web.archive.org\/web\/20170501183238\/http:\/\/hexatomium.github.io\/2016\/09\/24\/hidden-w10-pins\/."},{"key":"ref_21","unstructured":"(2020, July 27). Windows Update\u2014Interception. Available online: https:\/\/security.stackexchange.com\/questions\/31861\/windows-update-interception."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Arora, J.S. (2012). Introduction to Optimum Design, Academic Press. [3rd ed.].","DOI":"10.1016\/B978-0-12-381375-6.00004-8"}],"container-title":["Entropy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1099-4300\/23\/5\/507\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T05:51:51Z","timestamp":1760161911000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1099-4300\/23\/5\/507"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,4,23]]},"references-count":22,"journal-issue":{"issue":"5","published-online":{"date-parts":[[2021,5]]}},"alternative-id":["e23050507"],"URL":"https:\/\/doi.org\/10.3390\/e23050507","relation":{},"ISSN":["1099-4300"],"issn-type":[{"value":"1099-4300","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,4,23]]}}}