Research Article

Characterizing Anomalies in Malware-Generated HTTP Traffic

Table 8

Basic information about malicious pcap repositories.

FeatureCERT.plMCFPSum

No. of pcaps in repository36,26811736,385
No. of pcaps with HTTP network traffic26,0429126,133
No. of pcaps with HTTP network traffic containing requests alerted by IDS22,6306722,697
No. of reported IDS alerts2,133,682425,4412,559,123
No. of reported IDS alerts assigned to requests405,116238,805643,921
No. of unique alerted IDS rules578139642