Hybrid Botnet Detection Based on Host and Network Analysis

被引:23
|
作者
Almutairi, Suzan [1 ]
Mahfoudh, Saoucene [2 ]
Almutairi, Sultan [3 ]
Alowibdi, Jalal S. [4 ]
机构
[1] Tech & Vocat Corp, Riyadh, Saudi Arabia
[2] Dar Al Hekma Univ, Engn Comp & Informat, Jeddah, Saudi Arabia
[3] Technol Control Co, Riyadh, Saudi Arabia
[4] Univ Jeddah, Fac Comp & Informat Technol, Jeddah, Saudi Arabia
关键词
COMMAND;
D O I
10.1155/2020/9024726
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Botnet is one of the most dangerous cyber-security issues. The botnet infects unprotected machines and keeps track of the communication with the command and control server to send and receive malicious commands. The attacker uses botnet to initiate dangerous attacks such as DDoS, fishing, data stealing, and spamming. The size of the botnet is usually very large, and millions of infected hosts may belong to it. In this paper, we addressed the problem of botnet detection based on network's flows records and activities in the host. Thus, we propose a general technique capable of detecting new botnets in early phase. Our technique is implemented in both sides: host side and network side. The botnet communication traffic we are interested in includes HTTP, P2P, IRC, and DNS using IP fluxing. HANABot algorithm is proposed to preprocess and extract features to distinguish the botnet behavior from the legitimate behavior. We evaluate our solution using a collection of real datasets (malicious and legitimate). Our experiment shows a high level of accuracy and a low false positive rate. Furthermore, a comparison between some existing approaches was given, focusing on specific features and performance. The proposed technique outperforms some of the presented approaches in terms of accurately detecting botnet flow records within Netflow traces.
引用
收藏
页数:16
相关论文
共 50 条
  • [1] PodBot: A New Botnet Detection Method by Host and Network-Based Analysis
    Esmaeili, Somayeh
    Shahriari, Hamid Reza
    2019 27TH IRANIAN CONFERENCE ON ELECTRICAL ENGINEERING (ICEE 2019), 2019, : 1900 - 1904
  • [2] Botnet Detection with Hybrid Analysis on Flow Based and Graph Based Features of Network Traffic
    Shang, Yaoyao
    Yang, Shuangmao
    Wang, Wei
    CLOUD COMPUTING AND SECURITY, PT II, 2018, 11064 : 612 - 621
  • [3] IRC botnet detection based on host behavior
    Wang, Wei
    Fang, Bin-Xing
    Cui, Xiang
    Jisuanji Xuebao/Chinese Journal of Computers, 2009, 32 (10): : 1980 - 1988
  • [4] Botnet Host Detection Based on Heartbeat Association
    Ding Wei
    Hua Zidong
    Li Panhui
    Gong Qiushi
    Cheng Yuxi
    2020 4TH INTERNATIONAL CONFERENCE ON CRYPTOGRAPHY, SECURITY AND PRIVACY (ICCSP 2020), 2020, : 42 - 46
  • [5] AN APPROACH FOR HOST BASED BOTNET DETECTION SYSTEM
    Aleksieva, Yulia
    Valchanov, Hristo
    Aleksieva, Veneta
    2019 16TH CONFERENCE ON ELECTRICAL MACHINES, DRIVES AND POWER SYSTEMS (ELMA), 2019,
  • [6] Peer to Peer Botnet Detection Based on Network Traffic Analysis
    Almutairi, Suzan
    Mahfoudh, Saoucene
    Alowibdi, Jalal S.
    2016 8TH IFIP INTERNATIONAL CONFERENCE ON NEW TECHNOLOGIES, MOBILITY AND SECURITY (NTMS), 2016,
  • [7] Smart Approach for Botnet Detection Based on Network Traffic Analysis
    Obeidat, Alaa
    Yaqbeh, Rola
    JOURNAL OF ELECTRICAL AND COMPUTER ENGINEERING, 2022, 2022
  • [8] Botnet detection based on network behavior
    Strayer, W. Timothy
    Lapsely, David
    Walsh, Robert
    Livadas, Carl
    BOTNET DETECTION: COUNTERING THE LARGEST SECURITY THREAT, 2008, 36 : 1 - +
  • [9] Android Botnet Detection Using Hybrid Analysis
    Arhsad, Mamoona
    Karim, Ahmad
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2024, 18 (03): : 704 - 719
  • [10] Botnet sequential activity detection with hybrid analysis
    Putra, Muhammad Aidiel Rachman
    Ahmad, Tohari
    Hostiadi, Dandy Pramana
    Ijtihadie, Royyana Muslim
    EGYPTIAN INFORMATICS JOURNAL, 2024, 25