Research Article

HTTP-Based APT Malware Infection Detection Using URL Correlation Analysis

Table 1

Feature set for normal uncorrelated request filter.

FeatureDescription

URL lengthNumber of characters of the URL
URL entropyThe information entropy of the URL
Number of URL parametersNumber of parameters of the URL
TLDThe top-level domain of the URL
Domain entropyThe information entropy of the domain
Content typeContent type of the HTTP request
CookieDoes the HTTP request contain cookies?
User agentUser agent of the HTTP request