Botnet detection via mining of traffic flow characteristics

被引:60
|
作者
Kirubavathi, G. [1 ]
Anitha, R. [1 ]
机构
[1] PSG Coll Technol, Dept Appl Math & Computat Sci, Coimbatore, Tamil Nadu, India
关键词
Botnet detection; Network flows; Small packets; Packet ratio; Bot response packet ratio; Novelty detection;
D O I
10.1016/j.compeleceng.2016.01.012
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Botnet is one of the most serious threats to cyber security as it provides a distributed platform for several illegal activities. Regardless of the availability of numerous methods proposed to detect botnets, still it is a challenging issue as botmasters are continuously improving bots to make them stealthier and evade detection. Most of the existing detection techniques cannot detect modern botnets in an early stage, or they are specific to command and control protocol and structures. In this paper, we propose a novel approach to detect botnets irrespective of their structures, based on network traffic flow behavior analysis and machine learning techniques. The experimental evaluation of the proposed method with real-world benchmark datasets shows the efficiency of the method. Also, the system is able to identify the new botnets with high detection accuracy and low false positive rate. (C) 2016 Elsevier Ltd. All rights reserved.
引用
收藏
页码:91 / 101
页数:11
相关论文
共 50 条
  • [1] ARCHITECTURE FOR APPLYING DATA MINING AND VISUALIZATION ON NETWORK FLOW FOR BOTNET TRAFFIC DETECTION
    Shahrestani, Alireza
    Feily, Maryam
    Ahmad, Rodina
    Ramadass, Sureswaran
    PROCEEDINGS OF THE 2009 INTERNATIONAL CONFERENCE ON COMPUTER TECHNOLOGY AND DEVELOPMENT, VOL 1, 2009, : 33 - +
  • [2] Detection of botnet by analyzing network traffic flow characteristics using open source tools
    Shanthi, K.
    Seenivasan, D.
    PROCEEDINGS OF 2015 IEEE 9TH INTERNATIONAL CONFERENCE ON INTELLIGENT SYSTEMS AND CONTROL (ISCO), 2015,
  • [3] Automated Botnet Traffic Detection via Machine Learning
    Wai, Fok Kar
    Zheng Lilei
    Wai, Watt Kwong
    Le, Su
    Thing, Vrizlynn L. L.
    PROCEEDINGS OF TENCON 2018 - 2018 IEEE REGION 10 CONFERENCE, 2018, : 0038 - 0043
  • [4] Botnet detection based on traffic behavior analysis and flow intervals
    Zhao, David
    Traore, Issa
    Sayed, Bassam
    Lu, Wei
    Saad, Sherif
    Ghorbani, Ali
    Garant, Dan
    COMPUTERS & SECURITY, 2013, 39 : 2 - 16
  • [5] Flow Based Botnet Traffic Detection Using Machine Learning
    Gahelot, Parul
    Dayal, Neelam
    PROCEEDINGS OF ICETIT 2019: EMERGING TRENDS IN INFORMATION TECHNOLOGY, 2020, 605 : 418 - 426
  • [6] Flow-based Identification of Botnet Traffic by Mining Multiple Log Files
    Masud, Mohammad M.
    Al-Khateeb, Tahseen
    Khan, Latifur
    Thuraisingham, Bhavani
    Hamlen, Kevin W.
    DFMA 2008: FIRST INTERNATIONAL CONFERENCE ON DISTRIBUTED FRAMEWORKS & APPLICATIONS, PROCEEDINGS, 2008, : 200 - 206
  • [7] Botnet Detection Based on Traffic Monitoring
    Zeidanloo, Hossein Rouhani
    Manaf, Azizah Bt
    Vahdani, Payam
    Tabatabaei, Farzaneh
    Zamani, Mazdak
    2010 INTERNATIONAL CONFERENCE ON NETWORKING AND INFORMATION TECHNOLOGY (ICNIT 2010), 2010, : 97 - 101
  • [8] Centralized Botnet Detection by Traffic Aggregation
    Wang, Tao
    Yu, Shun-Zheng
    2009 IEEE INTERNATIONAL SYMPOSIUM ON PARALLEL AND DISTRIBUTED PROCESSING WITH APPLICATIONS, PROCEEDINGS, 2009, : 86 - 93
  • [9] IRC traffic analysis for botnet detection
    Mazzariello, Claudio
    FOURTH INTERNATIONAL SYMPOSIUM ON INFORMATION ASSURANCE AND SECURITY, PROCEEDINGS, 2008, : 318 - 323
  • [10] A Novel HTTP Botnet Traffic Detection Method
    Tyagi, Rohit
    Paul, Tuhin
    Manoj, B. S.
    Thanudas, B.
    2015 ANNUAL IEEE INDIA CONFERENCE (INDICON), 2015,