Multiclass Machine Learning Based Botnet Detection in Software Defined Networks

被引:0
|
作者
Tariq, Farhan [1 ]
Baig, Shamim [2 ]
机构
[1] Ctr Adv Studies Engn, Elect & Comp Engn, Islamabad, Pakistan
[2] HITEC Univ, Comp Sci & Engn, Taxila, Pakistan
关键词
botnet detection; malware; Multiclass machine learning; NBA; SDN; TSDR; OpenFlow; Opendaylight; flows;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Continuously evolving nature of botnet by using innovative approaches and technologies derives the need for continuous improvement of botnet detection solutions. The state of the art network approaches in literature targeting network header level information only for behavioral-based detection. These techniques applying machine learning algorithms to automatically detect botnet patterns from network flows. The current work in flow-based approaches exploring SDNs to overcome traditional IP network complexities. The Software defined network technology platform with centralized visibility and control provide an opportunity to redesign these approaches. The current SDNs based proposed approaches apply binary classification to decide if the detected flow belongs to a botnet or not. This work proposed a multiclass machine learning based approach to address botnet problem in SDNs. The proposed scheme applies multiple binary classifiers each trained for a specific type of botnet class. These focused classifiers performed better in the detection of the specific type of botnet. The proposed approach uses the flow trace concept. The features are extracted for each detected flow trace and fed into these focused classifiers. These features are examined by all classifiers and detected label is added for each processed flow trace. These labels are aggregated in the second stage to decide if a flow trace belongs to any botnet class or not. This additional information of a class of the detected botnet trace is helpful during the incident response process. The experiments for evaluation of the proposed work are performed on real-world traffic traces and the result shows promising detection rate with the capability to detect unknown botnet.
引用
收藏
页码:150 / 156
页数:7
相关论文
共 50 条
  • [41] Android botnet detection using machine learning
    Rasheed M.M.
    Faieq A.K.
    Hashim A.A.
    Rasheed, Mohammad M. (mohammad.rasheed@uoitc.edu.iq), 1600, International Information and Engineering Technology Association (25): : 127 - 130
  • [42] Study on Machine Learning Techniques for Botnet Detection
    Silva, L.
    Utimura, L.
    Costa, K.
    Silva, M.
    Prado, S.
    IEEE LATIN AMERICA TRANSACTIONS, 2020, 18 (05) : 881 - 888
  • [43] Botnet Detection via Machine Learning Techniques
    Wang, Haofan
    2022 INTERNATIONAL CONFERENCE ON BIG DATA, INFORMATION AND COMPUTER NETWORK (BDICN 2022), 2022, : 836 - 841
  • [44] An intelligent botnet blocking approach in software defined networks using honeypots
    Ja'fari, Forough
    Mostafavi, Seyedakbar
    Mizanian, Kiarash
    Jafari, Emad
    JOURNAL OF AMBIENT INTELLIGENCE AND HUMANIZED COMPUTING, 2021, 12 (02) : 2993 - 3016
  • [45] A GPU-based machine learning approach for detection of botnet attacks
    Motylinski, Michal
    MacDermott, Aine
    Iqbal, Farkhund
    Shah, Babar
    COMPUTERS & SECURITY, 2022, 123
  • [46] Botnet Detection Approach Using Graph-Based Machine Learning
    Alharbi, Afnan
    Alsubhi, Khalid
    IEEE ACCESS, 2021, 9 (09): : 99166 - 99180
  • [47] Explaining Machine Learning Predictions in Botnet Detection
    Miller, Sean
    Busby-Earle, Curtis
    ARTIFICIAL INTELLIGENCE AND SOFT COMPUTING, ICAISC 2022, PT I, 2023, 13588 : 298 - 309
  • [48] A Comprehensive Survey on Machine Learning using in Software Defined Networks (SDN)
    Sahar Faezi
    Alireza Shirmarz
    Human-Centric Intelligent Systems, 2023, 3 (3): : 312 - 343
  • [49] Network Traffic Classification Using Machine Learning for Software Defined Networks
    Kuranage, Menuka Perera Jayasuriya
    Piamrat, Kandaraj
    Hamma, Salima
    MACHINE LEARNING FOR NETWORKING (MLN 2019), 2020, 12081 : 28 - 39
  • [50] A Machine Learning Approach for Traffic Flow Provisioning in Software Defined Networks
    Kumar, Subham
    Bansal, Gaurang
    Shekhawat, Virendra Singh
    2020 34TH INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING (ICOIN 2020), 2020, : 602 - 607