Feature Selection for Effective Botnet Detection Based on Periodicity of Traffic

被引:1
|
作者
Harsha, T. [1 ]
Asha, S. [1 ]
Soniya, B. [1 ]
机构
[1] SCT Coll Engn, Dept Comp Sci & Engn, Trivandrum, Kerala, India
来源
INFORMATION SYSTEMS SECURITY | 2016年 / 10063卷
关键词
Botnet; C&C server; Periodicity; Bot; HTTP;
D O I
10.1007/978-3-319-49806-5_26
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Botnets are networks that are composed with a set of compromised machines called bots that are remotely controlled by a botmaster. They pose a threatening remark to network communications and applications. A botnet relies on its command and control communication channel for performing attacks. C2 traffic occurs prior to any attack; hence, the detection of botnet's traffic helps in detecting the bots before any real attack happens. Recently, the HTTP based Botnet threat has become a serious challenge for security experts as Bots can be distributed quickly and stealthily. The HTTP Bots periodically connect to particular web pages or URLs to get commands and updates from the Botmaster. In fact, this identifiable periodic connection pattern has been used to detect HTTP Botnets. This paper proposes an idea for identifying bots that exhibit non periodic nature as well normal traffic that exhibit periodic nature. The proposed method reduces the false positive rate as well as increases the detection rate. For that a set of traffic features are taken from many detection methods and feature selection is made on these features. Feature selection helps in enhancing the detection rate of the bot traffic in the network. For performing feature selection Principal Components Analysis is chosen. Top ranked features from PCA are added to existing work. Result shows improvement in detection rate and reduction in false positive rate.
引用
下载
收藏
页码:471 / 478
页数:8
相关论文
共 50 条
  • [31] ACNN-BOT: An Ant Colony Inspired Feature Selection Approach for ANN Based Botnet Detection
    Joshi, Chirag
    Ranjan, Ranjeet K.
    Bharti, Vishal
    WIRELESS PERSONAL COMMUNICATIONS, 2023, 132 (03) : 1999 - 2021
  • [32] Feature selection for IoT botnet detection using equilibrium and Battle Royale Optimization
    Bani Baker, Qanita
    Samarneh, Alaa
    Computers and Security, 2024, 147
  • [33] Machine learning and metaheuristic optimization algorithms for feature selection and botnet attack detection
    Mahdieh Maazalahi
    Soodeh Hosseini
    Knowledge and Information Systems, 2025, 67 (4) : 3549 - 3597
  • [34] Botnet detection based on traffic behavior analysis and flow intervals
    Zhao, David
    Traore, Issa
    Sayed, Bassam
    Lu, Wei
    Saad, Sherif
    Ghorbani, Ali
    Garant, Dan
    COMPUTERS & SECURITY, 2013, 39 : 2 - 16
  • [35] A Review of Botnet Detection Approaches Based on DNS Traffic Analysis
    Al-Mashhadi, Saif
    Anbar, Mohammed
    Karuppayah, Shankar
    Al-Ani, Ahmed K.
    INTELLIGENT AND INTERACTIVE COMPUTING, 2019, 67 : 305 - 321
  • [36] Smart Approach for Botnet Detection Based on Network Traffic Analysis
    Obeidat, Alaa
    Yaqbeh, Rola
    JOURNAL OF ELECTRICAL AND COMPUTER ENGINEERING, 2022, 2022
  • [37] An efficient botnet detection approach based on feature learning and classification
    Padmavathi, B.
    Muthukumar, B.
    JOURNAL OF CONTROL AND DECISION, 2023, 10 (01) : 40 - 53
  • [38] A Technique for the Botnet Detection Based on DNS-Traffic Analysis
    Pomorova, Oksana
    Savenko, Oleg
    Lysenko, Sergii
    Kryshchuk, Andrii
    Bobrovnikova, Kira
    COMPUTER NETWORKS, CN 2015, 2015, 522 : 127 - 138
  • [39] Flow Based Botnet Traffic Detection Using Machine Learning
    Gahelot, Parul
    Dayal, Neelam
    PROCEEDINGS OF ICETIT 2019: EMERGING TRENDS IN INFORMATION TECHNOLOGY, 2020, 605 : 418 - 426
  • [40] Combining MIC Feature Selection and Feature-based MSPCA for Network Traffic Anomaly Detection
    Chen, Zhaomin
    Yeo, Chai Kiat
    Francis, Bu Sung Lee
    Lau, Chiew Tong
    2016 THIRD INTERNATIONAL CONFERENCE ON DIGITAL INFORMATION PROCESSING, DATA MINING, AND WIRELESS COMMUNICATIONS (DIPDMWC), 2016, : 176 - 181