{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,4]],"date-time":"2026-07-04T17:59:27Z","timestamp":1783187967787,"version":"3.54.6"},"reference-count":26,"publisher":"IGI Global Scientific Publishing","issue":"4","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019,10]]},"abstract":"<jats:p>Nowadays, machine learning is popular in remote access Trojan (RAT) detection which can create patterns for decision-making. However, most research focus on improving the detection rate and reducing the false negative rate, therefore they ignore the result of abnormal samples. In addition, most classifiers select several proprietary applications and RATs as their training set, which makes them difficult to adapt to the real environment. In this article, the authors address the issue of imbalance dataset between normal and RAT samples, and propose a highly efficient method of detecting RATs in real traffic. In the authors method, they generate eight features by combining the size, the inter-arrival and the flag from one packet sequence. Then, they preprocess the imbalance dataset and implement a classifier by XGBoost algorithm. The classifier achieves a false negative rate of less than 0.18%. Moreover, the authors demonstrate that their classifier is capable of detecting unknown RAT.<\/jats:p>","DOI":"10.4018\/ijdcf.2019100101","type":"journal-article","created":{"date-parts":[[2019,9,27]],"date-time":"2019-09-27T06:10:22Z","timestamp":1569564622000},"page":"1-13","source":"Crossref","is-referenced-by-count":7,"title":["A Highly Efficient Remote Access Trojan Detection Method"],"prefix":"10.4018","volume":"11","author":[{"given":"Wei","family":"Jiang","sequence":"first","affiliation":[{"name":"Beijing University of Technology, Chinese Academy of Cyberspace Studies, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xianda","family":"Wu","sequence":"additional","affiliation":[{"name":"Beijing University of Technology, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiang","family":"Cui","sequence":"additional","affiliation":[{"name":"Guangzhou University, Guangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chaoge","family":"Liu","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"IJDCF.2019100101-0","doi-asserted-by":"crossref","unstructured":"Adachi, D., & Omote, K. (2016). A host-based detection method of remote access trojan in the early stage.","DOI":"10.1007\/978-3-319-49151-6_8"},{"issue":"3","key":"IJDCF.2019100101-1","first-page":"277","article-title":"An improved attack tree-based Trojan analysis and detection.","volume":"29","author":"N.Binru","year":"2014","journal-title":"Computer Application and Software"},{"key":"IJDCF.2019100101-2","doi-asserted-by":"publisher","DOI":"10.1613\/jair.953"},{"key":"IJDCF.2019100101-3","doi-asserted-by":"crossref","first-page":"785","DOI":"10.1145\/2939672.2939785","article-title":"Xgboost: A scalable tree boosting system.","author":"T.Chen","year":"2016","journal-title":"Proceedings of the 22nd ACM Sigkdd international conference on knowledge discovery and data mining"},{"key":"IJDCF.2019100101-4","doi-asserted-by":"crossref","unstructured":"Deng, P. S., Wang, J. H., Shieh, W. G., & Yen, C. P. (2003). Intelligent automatic malicious code signatures extraction. In IEEE, 2003 International Carnahan Conference on Security Technology Proceedings (pp. 600-603). IEEE.","DOI":"10.1109\/CCST.2003.1297626"},{"key":"IJDCF.2019100101-5","first-page":"770","author":"B.Farinholt","year":"2017","journal-title":"To Catch a Ratter: Monitoring the Behavior of Amateur DarkComet RAT Operators in the Wild. In Security and Privacy"},{"key":"IJDCF.2019100101-6","first-page":"79","author":"Y.Fukushima","year":"2010","journal-title":"A behavior based malware detection scheme for avoiding false positive. In Secure Network Protocols"},{"key":"IJDCF.2019100101-7","doi-asserted-by":"publisher","DOI":"10.1109\/AINA.2015.257"},{"key":"IJDCF.2019100101-8","author":"W. U.Jinlong","year":"2016","journal-title":"Hierarchical Detection of Trojan Behavior based on Random Forest"},{"key":"IJDCF.2019100101-9","unstructured":"Li, S., Yun, X., Zhang, Y., Pang, Y., & Yin, T. (2012). A novel approach of detecting Trojan based on network behavior analysis."},{"key":"IJDCF.2019100101-10","doi-asserted-by":"crossref","unstructured":"Liang, Y., Peng, G., Zhang, H., & Wang, Y. (2013). An Unknown Trojan Detection Method Based on Software Network Behavior. \u4e2d\u56fd\u53ef\u4fe1\u8ba1\u7b97\u4e0e\u4fe1\u606f\u5b89\u5168\u5b66\u672f\u4f1a\u8bae, 18, 369-376).","DOI":"10.1007\/s11859-013-0944-6"},{"key":"IJDCF.2019100101-11","author":"R.Liu","year":"2006","journal-title":"Optimizing the Hyper-parameters for SVM by Combining Evolution Strategies with a Grid Search. In Intelligent Control and Automation"},{"key":"IJDCF.2019100101-12","doi-asserted-by":"publisher","DOI":"10.1109\/CCNC.2009.4785028"},{"key":"IJDCF.2019100101-13","unstructured":"Mila Parkour. (2013). APT samples shared by Mila Parkour. Retrieved from https:\/\/www.mediafire.com\/?a49l965nlayad#734479hwy1b97"},{"key":"IJDCF.2019100101-14","unstructured":"Nuclear-EK-malware. (2014). A blog focuses on network traffic related to malware infections. Retrieved from http:\/\/www.malware-traffic-analysis.net\/2014\/index.html"},{"key":"IJDCF.2019100101-15","first-page":"3539","article-title":"Label propagation in big data to detect remote access Trojans.","author":"S. C.Pallaprolu","year":"2017","journal-title":"IEEE International Conference on Big Data"},{"issue":"03","key":"IJDCF.2019100101-16","first-page":"890","article-title":"Trojan detection method based on analysis of multiple data flow.","author":"X. U.Pan","year":"2015","journal-title":"Jisuanji Yingyong Yanjiu"},{"key":"IJDCF.2019100101-17","author":"G. J.Peng","year":"2012","journal-title":"Technology and implementation to detect unknown trojan based on network flow characteristics"},{"key":"IJDCF.2019100101-18","doi-asserted-by":"publisher","DOI":"10.1016\/j.procs.2013.05.106"},{"key":"IJDCF.2019100101-19","doi-asserted-by":"publisher","DOI":"10.1145\/1107622.1107655"},{"key":"IJDCF.2019100101-20","author":"L. I.Wei","year":"2015","journal-title":"Characteristics analysis of traffic behavior of remote access trojan in three communication phases"},{"key":"IJDCF.2019100101-21","first-page":"721","article-title":"A Novel Approach to Trojan Horse Detection by Process Tracing.","author":"N. Q.Wu","year":"2006","journal-title":"IEEE International Conference on Networking, Sensing and Control"},{"key":"IJDCF.2019100101-22","first-page":"311","article-title":"A Novel Anti-Trojan Approach using Behavioral Analysis.","author":"B.Xiang","year":"2009","journal-title":"International Conference on Apperceiving Computing and Intelligence Analysis"},{"key":"IJDCF.2019100101-23","doi-asserted-by":"publisher","DOI":"10.1109\/ICITST.2015.7412113"},{"key":"IJDCF.2019100101-24","doi-asserted-by":"publisher","DOI":"10.1145\/3028842.3028867"},{"key":"IJDCF.2019100101-25","first-page":"623","article-title":"Detecting Malicious Sessions Through Traffic Fingerprinting Using Hidden Markov Models.","author":"S.Zhioua","year":"2014","journal-title":"International Conference on Security and Privacy in Communication Systems"}],"container-title":["International Journal of Digital Crime and Forensics"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=238881","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,5,6]],"date-time":"2022-05-06T08:01:42Z","timestamp":1651824102000},"score":1,"resource":{"primary":{"URL":"http:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/IJDCF.2019100101"}},"subtitle":[""],"short-title":[],"issued":{"date-parts":[[2019,10]]},"references-count":26,"journal-issue":{"issue":"4"},"URL":"https:\/\/doi.org\/10.4018\/ijdcf.2019100101","relation":{},"ISSN":["1941-6210","1941-6229"],"issn-type":[{"value":"1941-6210","type":"print"},{"value":"1941-6229","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,10]]}}}