Feature Selection for Effective Botnet Detection Based on Periodicity of Traffic

被引:1
|
作者
Harsha, T. [1 ]
Asha, S. [1 ]
Soniya, B. [1 ]
机构
[1] SCT Coll Engn, Dept Comp Sci & Engn, Trivandrum, Kerala, India
来源
INFORMATION SYSTEMS SECURITY | 2016年 / 10063卷
关键词
Botnet; C&C server; Periodicity; Bot; HTTP;
D O I
10.1007/978-3-319-49806-5_26
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Botnets are networks that are composed with a set of compromised machines called bots that are remotely controlled by a botmaster. They pose a threatening remark to network communications and applications. A botnet relies on its command and control communication channel for performing attacks. C2 traffic occurs prior to any attack; hence, the detection of botnet's traffic helps in detecting the bots before any real attack happens. Recently, the HTTP based Botnet threat has become a serious challenge for security experts as Bots can be distributed quickly and stealthily. The HTTP Bots periodically connect to particular web pages or URLs to get commands and updates from the Botmaster. In fact, this identifiable periodic connection pattern has been used to detect HTTP Botnets. This paper proposes an idea for identifying bots that exhibit non periodic nature as well normal traffic that exhibit periodic nature. The proposed method reduces the false positive rate as well as increases the detection rate. For that a set of traffic features are taken from many detection methods and feature selection is made on these features. Feature selection helps in enhancing the detection rate of the bot traffic in the network. For performing feature selection Principal Components Analysis is chosen. Top ranked features from PCA are added to existing work. Result shows improvement in detection rate and reduction in false positive rate.
引用
下载
收藏
页码:471 / 478
页数:8
相关论文
共 50 条
  • [1] On Feature Selection Algorithms for Effective Botnet Detection
    Afroz, Meher
    Ibnath, Muntaka
    Rahman, Ashikur
    Sultana, Jakia
    Rab, Raqeebir
    UBIQUITOUS NETWORKING, UNET 2022, 2023, 13853 : 253 - 266
  • [2] On Feature Selection Algorithms for Effective Botnet Detection
    Afroz, Meher
    Ibnath, Muntaka
    Rahman, Ashikur
    Sultana, Jakia
    Rab, Raqeebir
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2024, 32 (02)
  • [3] Feature Selection Strategies for HTTP Botnet Traffic Detection
    Letteri, Ivan
    Della Penna, Giuseppe
    Caianiello, Pasquale
    2019 4TH IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (EUROS&PW), 2019, : 202 - 210
  • [4] Towards Effective Feature Selection in Machine Learning-Based Botnet Detection Approaches
    Beigi, Elaheh Biglar
    Jazi, Hossein Hadian
    Stakhanova, Natalia
    Ghorbani, Ali A.
    2014 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2014, : 247 - 255
  • [5] Clustering botnet communication traffic based on n-gram feature selection
    Lu, Wei
    Rammidi, Goaletsa
    Ghorbani, Ali A.
    COMPUTER COMMUNICATIONS, 2011, 34 (03) : 502 - 514
  • [6] Review of filtering based feature selection for Botnet detection in the Internet of Things
    Mohamed Saied
    Shawkat Guirguis
    Magda Madbouly
    Artificial Intelligence Review, 58 (4)
  • [7] Towards Effective Feature Selection for IoT Botnet Attack Detection Using a Genetic Algorithm
    Liu, Xiangyu
    Du, Yanhui
    ELECTRONICS, 2023, 12 (05)
  • [8] Botnet Detection Based on Traffic Monitoring
    Zeidanloo, Hossein Rouhani
    Manaf, Azizah Bt
    Vahdani, Payam
    Tabatabaei, Farzaneh
    Zamani, Mazdak
    2010 INTERNATIONAL CONFERENCE ON NETWORKING AND INFORMATION TECHNOLOGY (ICNIT 2010), 2010, : 97 - 101
  • [9] Generic Feature Selection Measure for Botnet Malware Detection
    Berg, Peter Ekstrand
    Franke, Katrin
    Hai Thanh Nguyen
    2012 12TH INTERNATIONAL CONFERENCE ON INTELLIGENT SYSTEMS DESIGN AND APPLICATIONS (ISDA), 2012, : 711 - 717
  • [10] Fast-flux Botnet Detection Method Based on Spatiotemporal Feature of Network Traffic
    Niu Weina
    Jiang Tianyu
    Zhang Xiaosong
    Xie Jiao
    Zhang Junzhe
    Zhao Zhenfei
    JOURNAL OF ELECTRONICS & INFORMATION TECHNOLOGY, 2020, 42 (08) : 1872 - 1880