Research Article

Characterizing Anomalies in Malware-Generated HTTP Traffic

Table 16

The payload entropy statistics for HTTP requests (malicious traffic) in bits.

CategoryMedianMean1st quartile3rd quartileMin valueMax value

Backdoor5.865.855.865.864.085.96
Banker5.426.115.427.351.007.86
Bruteforce4.274.324.274.354.247.63
Clicker5.915.885.895.924.295.96
DDoS4.314.314.314.314.314.31
Downloader6.156.415.067.763.888.00
Keylogger4.965.054.965.141.827.63
Miner5.525.475.515.533.605.99
PUA/Adware4.214.454.214.214.217.95
Ransomware4.444.484.394.483.517.53
RAT4.994.974.785.004.455.89
Spambot7.106.846.777.163.858.00
Stealer6.005.244.296.034.116.68
Trojan5.815.394.365.821.007.99
UA problem4.985.044.875.134.655.63

Note. The statistics were counted using all requests in the particular malware category, without being organized into request groups.