[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-118247-en":3,"doc-seo-118247-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},118247,1099514068035,"Ezra","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",8,"Research & Report","Enhancing Cybersecurity with Machine Learning - Beaconing Detection in PCAP Data - Bachelor Thesis","This study enhances cybersecurity by applying machine learning to detect beaconing activity in network traffic stored as PCAP (packet capture). Beaconing is a discreet, repetitive malware communication pattern used to contact a Command and Control (C2) server, often blending into legitimate traffic and remaining hidden for long periods. A dual-model framework combines a Histogram Gradient Boosting Classifier (HGBC) for feature-based initial classification and an LSTM neural network to model temporal dependencies across consecutive packet flows. The combined approach achieves 99.37% accuracy on a tailored dataset, demonstrating strong potential for threat identification in PCAP analysis.","Enhancing Cybersecurity with Machine Learning: Beaconing Detection in PCAP Data  \nBachelor Thesis  \nDepartment of Computer Science  \nOST – Eastern Switzerland University of Applied Sciences Campus Rapperswil-Jona  \nSpring Term 2024  \nAuthor Anastasiia Graftceva  \nAdvisor Nikolaus Heners  \nExternal Expert Ludovico Bessi Internal Expert Stefan Kapferer  \nAcknowledgements  \nI would like to extend my gratitude to the following individuals for their contributions to this study:  \nFirstly, I would like to thank Nikolaus Heners for allowing me to undertake this project, his unwavering support throughout the term, and his spot-on ideas. His belief in my abilities and selection of me for this topic, despite the competition, has been a signiﬁcant motivating factor throughout this journey.  \nSecondly, my sincere thanks to Ludovico Bessi and Stefan Kapferer for their insightful questions, valuable inputs, and expert advice. Their critical feedback has been instrumental in reﬁning my research and improving the quality of this paper.  \nLastly, I am deeply grateful to my husband Marc for his constant support, cheer-ups, and motivation. His understanding and encouragement have provided me with the emotional strength and balance necessary to complete this work.  \nAbstract  \nThis study explores the enhancement of cybersecurity through the application of machine learning techniques, speciﬁcally focusing on the detection of beaconing activity in network traﬃc (PCAP) data. PCAP, or packet capture, refers to the process of intercepting and logging traﬃc that passes over a computer network.  \nBeaconing, a communication technique and a common indicator of malicious activity requires complex multilevel detection methods due to its discreet and repetitive nature. My approach involves the development of a dual-model framework with a combination of a Histogram Gradient Booster Classiﬁer (HGBC) and a Long Short-Term Memory (LSTM) neural network. The HGBC classiﬁes the initial features extracted from the PCAP data, while the LSTM model further reﬁnes the detection by capturing temporal dependencies between consecutive packet ﬂows.  \nThe combined model achieves an accuracy rate of 99.37%, demonstrating its eﬀectiveness in identifying beaconing patterns. This high level of accuracy illustrates the potential of a combination of machine learning and deep learning algorithms in advancing cybersecurity measures for unmasking threats in network traﬃc analysis.  \nManagement Summary  \nOverview  \nThis study explores the application of advanced Machine Learning (ML) and Deep Learning (DL) methods for detecting malicious patterns in network captures (PCAP), focusing speciﬁcally on beaconing. Beaconing is a communication technique where malware intermittently sends signals to an external server, known as Command and Control (C2), often to receive instructions or exﬁltrate data. Detecting beaconing is challenging due to its low-frequency, regular communication patterns that blend in with legitimate traﬃc. This discreet behavior makes it a signiﬁcant threat, as the malware can remain undetected for long periods, facilitating extensive data breaches.  \nObjective of the Study  \nThe goal of this project is to develop a dual-model framework that integrates a Histogram Gradient Boosting Classiﬁer (HGBC) and a Long Short-Term Memory (LSTM) neural network. The HGBC, an ML algorithm based on decision trees, is designed to identify presence of malicious periodic signals based on PCAP data features analysis, while the LSTM neural network detects temporal dependencies in sequential data for more accurate results.  \nKey Findings  \n• Model Accuracy: The dual-model framework achieves an accuracy rate of 99.37% on the tailor-made dataset  \n• Performance: The model correctly identiﬁes beaconing patterns in ﬁles containing malicious content and accurately recognises benign ﬁles.  \n• ML Classiﬁer Eﬃciency: The HGBC uses histograms to speed up training by considering unique values when loo","cbCaikgE4gEKnJqq","https://ap.wps.com/l/cbCaikgE4gEKnJqq","pdf",2037261,1,40,"English","en",105,"# Acknowledgements\n# Abstract\n# Management Summary\n## Overview\n## Objective of the Study\n## Key Findings\n## Approach\n## Implications and Recommendations","[{\"question\":\"What is beaconing and why is it hard to detect in PCAP data?\",\"answer\":\"Beaconing is an intermittent malware communication pattern that signals an external Command and Control (C2) server. It is challenging because it follows low-frequency, regular behaviors that can resemble legitimate network traffic.\"},{\"question\":\"How does the proposed dual-model framework work?\",\"answer\":\"The framework uses a Histogram Gradient Boosting Classifier (HGBC) to classify initial features extracted from PCAP-derived flow data, then an LSTM model to refine detection by capturing temporal dependencies between consecutive packet flows.\"},{\"question\":\"What performance results does the study report?\",\"answer\":\"The combined model achieves an accuracy rate of 99.37% on a tailored dataset and correctly distinguishes beaconing patterns in malicious content from benign files.\"}]","Enhancing Cybersecurity with Machine Learning - Beaconing Detection in PCAP Data - Bachelor Thesis | PDF",1785682626,101,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"enhancing-cybersecurity-with-machine-learning-beaconing-detection-in-pcap-data-bachelor-thesis","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/enhancing-cybersecurity-with-machine-learning-beaconing-detection-in-pcap-data-bachelor-thesis/118247/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-05","2026-08-02",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What is beaconing and why is it hard to detect in PCAP data?","Question",{"text":76,"@type":77},"Beaconing is an intermittent malware communication pattern that signals an external Command and Control (C2) server. It is challenging because it follows low-frequency, regular behaviors that can resemble legitimate network traffic.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How does the proposed dual-model framework work?",{"text":81,"@type":77},"The framework uses a Histogram Gradient Boosting Classifier (HGBC) to classify initial features extracted from PCAP-derived flow data, then an LSTM model to refine detection by capturing temporal dependencies between consecutive packet flows.",{"name":83,"@type":74,"acceptedAnswer":84},"What performance results does the study report?",{"text":85,"@type":77},"The combined model achieves an accuracy rate of 99.37% on a tailored dataset and correctly distinguishes beaconing patterns in malicious content from benign files.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":93},[94,98,102,106,111,116,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":46,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":112,"doc_module":4,"doc_module_name":46,"category_name":113,"show_sort_weight":114,"slug":115},6,"Technology",50,"technology",{"id":117,"doc_module":4,"doc_module_name":46,"category_name":118,"show_sort_weight":21,"slug":119},7,"Healthcare","healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":107,"slug":138},19,"General","general"]