Research Article

Characterizing Anomalies in Malware-Generated HTTP Traffic

Table 11

Top 10 headers in a request (benign traffic).

BrowserHeader name-percentage of requests
“Host”“User-Agent”“Connection”“Accept”“Accept-Encoding”“Accept-Language”“Referer”“Cookie”“DNT”“Upgrade-Insecure-Requests”

Edge Win10100.0099.89100.0099.8696.8095.4691.0548.641.070.00
Chrome Win7100.00100.00100.0099.7999.6299.1695.6255.190.006.12
Firefox-FP Win7100.00100.00100.00100.0099.9699.8493.9748.300.007.35
Firefox Win7100.00100.00100.0099.9999.9298.1293.8648.050.005.64
IE11 Win799.9999.9999.9999.9892.9091.9888.3343.8878.480.00
Chrome Win8.1100.00100.0099.7899.4699.3997.7893.6452.020.006.81
Firefox Win8.1100.00100.0099.8299.8399.7899.7794.0149.620.007.31
IE11 Win8.199.9999.9999.7499.7093.9192.9888.6544.0280.260.00
Average100.0099.9999.9399.8397.7196.7792.4148.8321.544.13