Multiclass Machine Learning Based Botnet Detection in Software Defined Networks

被引:0
|
作者
Tariq, Farhan [1 ]
Baig, Shamim [2 ]
机构
[1] Ctr Adv Studies Engn, Elect & Comp Engn, Islamabad, Pakistan
[2] HITEC Univ, Comp Sci & Engn, Taxila, Pakistan
关键词
botnet detection; malware; Multiclass machine learning; NBA; SDN; TSDR; OpenFlow; Opendaylight; flows;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Continuously evolving nature of botnet by using innovative approaches and technologies derives the need for continuous improvement of botnet detection solutions. The state of the art network approaches in literature targeting network header level information only for behavioral-based detection. These techniques applying machine learning algorithms to automatically detect botnet patterns from network flows. The current work in flow-based approaches exploring SDNs to overcome traditional IP network complexities. The Software defined network technology platform with centralized visibility and control provide an opportunity to redesign these approaches. The current SDNs based proposed approaches apply binary classification to decide if the detected flow belongs to a botnet or not. This work proposed a multiclass machine learning based approach to address botnet problem in SDNs. The proposed scheme applies multiple binary classifiers each trained for a specific type of botnet class. These focused classifiers performed better in the detection of the specific type of botnet. The proposed approach uses the flow trace concept. The features are extracted for each detected flow trace and fed into these focused classifiers. These features are examined by all classifiers and detected label is added for each processed flow trace. These labels are aggregated in the second stage to decide if a flow trace belongs to any botnet class or not. This additional information of a class of the detected botnet trace is helpful during the incident response process. The experiments for evaluation of the proposed work are performed on real-world traffic traces and the result shows promising detection rate with the capability to detect unknown botnet.
引用
收藏
页码:150 / 156
页数:7
相关论文
共 50 条
  • [31] A Machine Learning-Based Anomaly Prediction Service for Software-Defined Networks
    Latif, Zohaib
    Umer, Qasim
    Lee, Choonhwa
    Sharif, Kashif
    Li, Fan
    Biswas, Sujit
    SENSORS, 2022, 22 (21)
  • [32] Machine-learning based Threat-aware System in Software Defined Networks
    Song, Chungsik
    Park, Younghee
    Golani, Keyur
    Kim, Youngsoo
    Bhatt, Kalgi
    Goswami, Kunal
    2017 26TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATION AND NETWORKS (ICCCN 2017), 2017,
  • [33] A machine learning software tool for multiclass classification
    Wang, Shangzhou
    Lu, Haohui
    Khan, Arif
    Hajati, Farshid
    Khushi, Matloob
    Uddin, Shahadat
    SOFTWARE IMPACTS, 2022, 13
  • [34] Restricted Boltzmann Machine based Detection System for DDoS attack in Software Defined Networks
    MohanaPriya, P.
    Shalinie, S. Mercy
    2017 FOURTH INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING, COMMUNICATION AND NETWORKING (ICSCN), 2017,
  • [35] Traffic Feature Selection and Distributed Denial of Service Attack Detection in Software-Defined Networks Based on Machine Learning
    Han, Daoqi
    Li, Honghui
    Fu, Xueliang
    Zhou, Shuncheng
    SENSORS, 2024, 24 (13)
  • [36] Machine Learning-Based Multiclass Anomaly Detection and Classification in Hybrid Active Distribution Networks
    Chandio, Sadullah
    Laghari, Javed Ahmed
    Bhayo, Muhammad Akram
    Koondhar, Mohsin Ali
    Kim, Yun-Su
    Graba, Besma Bechir
    Touti, Ezzeddine
    IEEE ACCESS, 2024, 12 : 120131 - 120141
  • [37] In-Depth Feature Selection for the Statistical Machine Learning-Based Botnet Detection in IoT Networks
    Kalakoti, Rajesh
    Nomm, Sven
    Bahsi, Hayretdin
    IEEE ACCESS, 2022, 10 : 94518 - 94535
  • [38] Detecting P2P Botnet in Software Defined Networks
    Su, Shang-Chiuan
    Chen, Yi-Ren
    Tsai, Shi-Chun
    Lin, Yi-Bing
    SECURITY AND COMMUNICATION NETWORKS, 2018,
  • [39] Dynamics of Botnet Propagation in Software Defined Networks Using Epidemic Models
    Balarezo, Juan Fernando
    Wang, Song
    Chavez, Karina Gomez
    Al-Hourani, Akram
    Kandeepan, Sithamparanathan
    IEEE ACCESS, 2021, 9 : 119406 - 119417
  • [40] An intelligent botnet blocking approach in software defined networks using honeypots
    Forough Ja’fari
    Seyedakbar Mostafavi
    Kiarash Mizanian
    Emad Jafari
    Journal of Ambient Intelligence and Humanized Computing, 2021, 12 : 2993 - 3016