Botnet Detection Approach Using Graph-Based Machine Learning

被引:25
|
作者
Alharbi, Afnan [1 ]
Alsubhi, Khalid [1 ]
机构
[1] King Abdulaziz Univ, Fac Comp & Informat Technol, Dept Comp Sci, Jeddah 21589, Saudi Arabia
关键词
Botnet; Feature extraction; Payloads; Malware; Training; Monitoring; Protocols; Botnet detection; cybersecurity; feature selection; machine learning; INTRUSION DETECTION; FEATURE-SELECTION; INFORMATION; ALGORITHM; NETWORK; SCHEME;
D O I
10.1109/ACCESS.2021.3094183
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Detecting botnet threats has been an ongoing research endeavor. Machine Learning (ML) techniques have been widely used for botnet detection with flow-based features. The prime challenges with flow-based features are that they have high computational overhead and do not fully capture network communication patterns. Recently, graph-based ML has witnessed a dramatic increase in attention. In communication networks, graph data offers insights information about communication patterns between hosts. In this paper, we propose a graph-based ML model for botnet detection that first considers the significance of graph features before developing a generalized model for detecting botnets based on the selected important features. We explore different feature sets selected using five filter-based feature evaluation measures derived from various theories such as consistency, correlation, and information. Two heterogeneous botnet datasets, CTU-13 and IoT-23, were used to evaluate the effectiveness of the proposed graph-based botnet detection with several supervised ML algorithms. Experiment results show that using features reduces training time and model complexity and provides high bots detection rate. Our proposed detection model detects different types of botnet families and exhibits robustness to zero-day attacks. Compared to state-of-the-art techniques flow-, and graph-based, our approach achieves higher precision and shows competitive accuracy.
引用
收藏
页码:99166 / 99180
页数:15
相关论文
共 50 条
  • [1] A novel graph-based approach for IoT botnet detection
    Huy-Trung Nguyen
    Quoc-Dung Ngo
    Van-Hoang Le
    [J]. International Journal of Information Security, 2020, 19 : 567 - 577
  • [2] A novel graph-based approach for IoT botnet detection
    Huy-Trung Nguyen
    Quoc-Dung Ngo
    Van-Hoang Le
    [J]. INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2020, 19 (05) : 567 - 577
  • [3] A Graph-Based Machine Learning Approach for Bot Detection
    Abou Daya, Abbas
    Salahuddin, Mohammad A.
    Limam, Noura
    Boutaba, Raouf
    [J]. 2019 IFIP/IEEE SYMPOSIUM ON INTEGRATED NETWORK AND SERVICE MANAGEMENT (IM), 2019, : 144 - 152
  • [4] DETECTING BOTNET VICTIMS THROUGH GRAPH-BASED MACHINE LEARNING
    Millar, Kyle
    Simpson, Lachlan
    Cheng, Adriel
    Chew, Hong Gunn
    Lim, Cheng-Chew
    [J]. PROCEEDINGS OF 2021 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS (ICMLC), 2021, : 46 - 51
  • [5] Botnet detection using graph-based feature clustering
    Chowdhury S.
    Khanzadeh M.
    Akula R.
    Zhang F.
    Zhang S.
    Medal H.
    Marufuzzaman M.
    Bian L.
    [J]. Journal of Big Data, 4 (1)
  • [6] BotChase: Graph-Based Bot Detection Using Machine Learning
    Abou Daya, Abbas
    Salahuddin, Mohammad A.
    Limam, Noura
    Boutaba, Raouf
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2020, 17 (01): : 15 - 29
  • [7] An Approach for Detection of Botnet Based on Machine Learning Classifier
    Tikekar P.C.
    Sherekar S.S.
    Kumar J.
    [J]. SN Computer Science, 5 (3)
  • [8] A Machine Learning approach for Graph-based Page Segmentation
    Maia, Ana L. L. M.
    Julca-Aguilar, Frank D.
    Hirata, Nina S. T.
    [J]. PROCEEDINGS 2018 31ST SIBGRAPI CONFERENCE ON GRAPHICS, PATTERNS AND IMAGES (SIBGRAPI), 2018, : 424 - 431
  • [9] BotSward: Centrality Measures for Graph-Based Bot Detection Using Machine Learning
    Shinan, Khlood
    Alsubhi, Khalid
    Ashraf, M. Usman
    [J]. CMC-COMPUTERS MATERIALS & CONTINUA, 2023, 74 (01): : 693 - 714
  • [10] Towards effectively feature graph-based IoT botnet detection via reinforcement learning
    Quoc-Dung Ngo
    Huy-Trung Nguyen
    Le-Cuong Nguyen
    [J]. JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2021, 41 (06) : 6801 - 6814