Hybrid Botnet Detection Based on Host and Network Analysis

被引:23
|
作者
Almutairi, Suzan [1 ]
Mahfoudh, Saoucene [2 ]
Almutairi, Sultan [3 ]
Alowibdi, Jalal S. [4 ]
机构
[1] Tech & Vocat Corp, Riyadh, Saudi Arabia
[2] Dar Al Hekma Univ, Engn Comp & Informat, Jeddah, Saudi Arabia
[3] Technol Control Co, Riyadh, Saudi Arabia
[4] Univ Jeddah, Fac Comp & Informat Technol, Jeddah, Saudi Arabia
关键词
COMMAND;
D O I
10.1155/2020/9024726
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Botnet is one of the most dangerous cyber-security issues. The botnet infects unprotected machines and keeps track of the communication with the command and control server to send and receive malicious commands. The attacker uses botnet to initiate dangerous attacks such as DDoS, fishing, data stealing, and spamming. The size of the botnet is usually very large, and millions of infected hosts may belong to it. In this paper, we addressed the problem of botnet detection based on network's flows records and activities in the host. Thus, we propose a general technique capable of detecting new botnets in early phase. Our technique is implemented in both sides: host side and network side. The botnet communication traffic we are interested in includes HTTP, P2P, IRC, and DNS using IP fluxing. HANABot algorithm is proposed to preprocess and extract features to distinguish the botnet behavior from the legitimate behavior. We evaluate our solution using a collection of real datasets (malicious and legitimate). Our experiment shows a high level of accuracy and a low false positive rate. Furthermore, a comparison between some existing approaches was given, focusing on specific features and performance. The proposed technique outperforms some of the presented approaches in terms of accurately detecting botnet flow records within Netflow traces.
引用
收藏
页数:16
相关论文
共 50 条
  • [41] Mobile Botnet Detection Using Network Forensics
    Vural, Ickin
    Venter, Hein
    FUTURE INTERNET-FIS 2010, 2010, 6369 : 57 - 67
  • [42] Botnet Detection Based on Anomaly and Community Detection
    Wang, Jing
    Paschalidis, Ioannis Ch.
    IEEE TRANSACTIONS ON CONTROL OF NETWORK SYSTEMS, 2017, 4 (02): : 392 - 404
  • [43] Botnet attack detection in IoT using hybrid optimisation enabled deep stacked autoencoder network
    Kalidindi, Archana
    Arrama, Mahesh Babu
    INTERNATIONAL JOURNAL OF BIO-INSPIRED COMPUTATION, 2023, 22 (02) : 77 - 88
  • [44] Method for botnet detection with small labelled samples based on graph neural network
    Zhu, Junjing
    Lin, Honggang
    INTERNATIONAL JOURNAL OF INFORMATION AND COMPUTER SECURITY, 2025, 26 (1-2)
  • [45] Network Flow based IoT Botnet Attack Detection using Deep Learning
    Sriram, S.
    Vinayakumar, R.
    Alazab, Mamoun
    Soman, K. P.
    IEEE INFOCOM 2020 - IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (INFOCOM WKSHPS), 2020, : 189 - 194
  • [46] Botnet Detection Based on Generative Adversarial Network and Efficient Lifelong Learning Algorithm
    Song, Chunyang
    Wushouer, Mairidan
    Tuerho, Gulanbaier
    2022 INTERNATIONAL CONFERENCE ON BIG DATA, INFORMATION AND COMPUTER NETWORK (BDICN 2022), 2022, : 48 - 54
  • [47] Deep reinforcement learning based Evasion Generative Adversarial Network for botnet detection
    Randhawa, Rizwan Hamid
    Aslam, Nauman
    Alauthman, Mohammad
    Khalid, Muhammad
    Rafiq, Husnain
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2024, 150 : 294 - 302
  • [48] Particle Swarm Optimization Algorithm Based Artificial Neural Network for Botnet Detection
    P. Panimalar
    Wireless Personal Communications, 2021, 121 : 2655 - 2666
  • [49] A review on graph-based approaches for network security monitoring and botnet detection
    Sofiane Lagraa
    Martin Husák
    Hamida Seba
    Satyanarayana Vuppala
    Radu State
    Moussa Ouedraogo
    International Journal of Information Security, 2024, 23 : 119 - 140
  • [50] A review on graph-based approaches for network security monitoring and botnet detection
    Lagraa, Sofiane
    Husak, Martin
    Seba, Hamida
    Vuppala, Satyanarayana
    State, Radu
    Ouedraogo, Moussa
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2024, 23 (01) : 119 - 140