PASSVM: A highly accurate fast flux detection system

被引:3
|
作者
Al-Duwairi, Basheer [1 ]
Jarrah, Moath [2 ]
Shatnawi, Ahmed S. [3 ]
机构
[1] Jordan Univ Sci & Technol, Dept Network Engn & Secur, Irbid, Jordan
[2] Jordan Univ Sci & Technol, Dept Comp Engn, Irbid, Jordan
[3] Jordan Univ Sci & Technol, Dept Software Engn, Irbid, Jordan
关键词
Fast-flux; Botnets; Network security; Artificial neural networks; Support vector machine; Radial basis function kernel; MULTILAYER PERCEPTRON; NETWORKS; CLASSIFICATION; DESIGN;
D O I
10.1016/j.cose.2021.102431
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Fast Flux service networks (FFSNs) are used by adversaries to provide high availability to malicious servers while keeping them hidden from direct access. In these networks, a large number of botnet machines work as proxies to relay the traffic between end users and a ma-licious mothership server which is controlled by an adversary. Various mechanisms have been proposed for detecting FFSNs. However, most of these mechanisms depend on col-lecting a large amount of DNS traffic traces and require a considerable amount of time to identify fast flux domains. In this paper, we propose an efficient AI-based online fast flux detection system that performs highly accurate and extremely fast detection of fast flux do-mains. The proposed system, called PASSVM, is based on features that are associated with DNS response messages of a given domain name. The approach relies on features that are stored in local databases, in addition to features that are extracted from the response DNS messages. The information in the databases are obtained from Censys search engine and an IP Geolocation service. PASSVM is evaluated using three types of supervised machine learn-ing algorithms which are: Multilayer Perceptron (MLP), Radial Basis Function Network (RBF), and Support Vector Machines (SVM). Results show that SVM with RBF kernel outperformed the other two methods with an accuracy of 99.557% and a detection time of less than 18 ms. (c) 2021 Elsevier Ltd. All rights reserved.
引用
收藏
页数:15
相关论文
共 50 条
  • [1] A Fast and Highly Accurate Battery Charger With Accurate Built-In Resistance Detection
    Jung, Young-Ho
    Jung, Jae-Hyung
    Jeong, Hoe-Eung
    Jung, Jae-Hoon
    An, Jae-Sung
    Ahn, Hyun-A.
    Hong, Seong-Kwan
    Kwon, Oh-Kyong
    IEEE TRANSACTIONS ON POWER ELECTRONICS, 2018, 33 (12) : 10051 - 10054
  • [2] A Fast and Accurate FPGA based QRS detection System
    Shukla, Ashish
    Macchiarulo, Luca
    2008 30th Annual International Conference of the IEEE Engineering in Medicine and Biology Society, Vols 1-8, 2008, : 4828 - 4831
  • [3] A Mobile Vision System for Fast and Accurate Ellipse Detection
    Fornaciari, Michele
    Cucchiara, Rita
    Prati, Andrea
    2013 IEEE CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION WORKSHOPS (CVPRW), 2013, : 52 - +
  • [4] Highly accurate and fast YOLOv4-based polyp detection✩
    Carrinho, Pedro
    Falcao, Gabriel
    EXPERT SYSTEMS WITH APPLICATIONS, 2023, 232
  • [5] An Accurate and Fast Animal Species Detection System for Embedded Devices
    Ibraheam, Mai
    Li, Kin Fun
    Gebali, Fayez
    IEEE ACCESS, 2023, 11 : 23462 - 23473
  • [6] GFlux: A Google-Based System for Fast Flux Detection
    Al-Duwairi, Basheer
    Al-Hammouri, Ahmad
    Aldwairi, Monther
    Paxson, Vern
    2015 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2015, : 755 - 756
  • [8] Fast and Highly Accurate RF Phase Detector with Analog Integrator for APAA System
    Hirai, Akihito
    Tsutsumi, Koji
    Takahashi, Yoshinori
    Nakamizo, Hideyuki
    Tajima, Kenichi
    Taniguchi, Eiji
    Shimozawa, Mitsuhiro
    Hieda, Morishige
    Nakayama, Masatoshi
    2013 ASIA-PACIFIC MICROWAVE CONFERENCE PROCEEDINGS (APMC 2013), 2013, : 1 - 3
  • [9] A Survey of Fast Flux Botnet Detection With Fast Flux Cloud Computing
    Al-Nawasrah, Ahmad
    Almomani, Ammar Ali
    Atawneh, Samer
    Alauthman, Mohammad
    INTERNATIONAL JOURNAL OF CLOUD APPLICATIONS AND COMPUTING, 2020, 10 (03) : 17 - 53
  • [10] Fast Flux Watch: A mechanism for online detection of fast flux networks
    Al-Duwairi, Basheer N.
    Al-Hammouri, Ahmad T.
    JOURNAL OF ADVANCED RESEARCH, 2014, 5 (04) : 473 - 479