PASSVM: A highly accurate fast flux detection system

被引:3
|
作者
Al-Duwairi, Basheer [1 ]
Jarrah, Moath [2 ]
Shatnawi, Ahmed S. [3 ]
机构
[1] Jordan Univ Sci & Technol, Dept Network Engn & Secur, Irbid, Jordan
[2] Jordan Univ Sci & Technol, Dept Comp Engn, Irbid, Jordan
[3] Jordan Univ Sci & Technol, Dept Software Engn, Irbid, Jordan
关键词
Fast-flux; Botnets; Network security; Artificial neural networks; Support vector machine; Radial basis function kernel; MULTILAYER PERCEPTRON; NETWORKS; CLASSIFICATION; DESIGN;
D O I
10.1016/j.cose.2021.102431
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Fast Flux service networks (FFSNs) are used by adversaries to provide high availability to malicious servers while keeping them hidden from direct access. In these networks, a large number of botnet machines work as proxies to relay the traffic between end users and a ma-licious mothership server which is controlled by an adversary. Various mechanisms have been proposed for detecting FFSNs. However, most of these mechanisms depend on col-lecting a large amount of DNS traffic traces and require a considerable amount of time to identify fast flux domains. In this paper, we propose an efficient AI-based online fast flux detection system that performs highly accurate and extremely fast detection of fast flux do-mains. The proposed system, called PASSVM, is based on features that are associated with DNS response messages of a given domain name. The approach relies on features that are stored in local databases, in addition to features that are extracted from the response DNS messages. The information in the databases are obtained from Censys search engine and an IP Geolocation service. PASSVM is evaluated using three types of supervised machine learn-ing algorithms which are: Multilayer Perceptron (MLP), Radial Basis Function Network (RBF), and Support Vector Machines (SVM). Results show that SVM with RBF kernel outperformed the other two methods with an accuracy of 99.557% and a detection time of less than 18 ms. (c) 2021 Elsevier Ltd. All rights reserved.
引用
收藏
页数:15
相关论文
共 50 条
  • [41] Online Near-Duplicate Video Clip Detection and Retrieval: An Accurate and Fast System
    Huang, Zi
    Wang, Liping
    Shen, Heng Tao
    Shao, Jie
    Zhou, Xiaofang
    ICDE: 2009 IEEE 25TH INTERNATIONAL CONFERENCE ON DATA ENGINEERING, VOLS 1-3, 2009, : 1511 - 1514
  • [42] Fast-flux hunter: a system for filtering online fast-flux botnet
    Almomani, Ammar
    NEURAL COMPUTING & APPLICATIONS, 2018, 29 (07): : 483 - 493
  • [43] Fast-flux hunter: a system for filtering online fast-flux botnet
    Ammar Almomani
    Neural Computing and Applications, 2018, 29 : 483 - 493
  • [44] Botnet Attack Detection Using A Hybrid Supervised Fast-Flux Killer System
    Al-Nawasrah, Ahmad
    Almomani, Ammar
    Al-Issa, Huthaifa A.
    Alissa, Khalid
    Alrosan, Ayat
    Alaboudi, Abdulellah A.
    Gupta, Brij B.
    JOURNAL OF WEB ENGINEERING, 2022, 21 (02): : 179 - 201
  • [45] Hybrid Detection and Tracking of Fast-Flux Botnet on Domain Name System Traffic
    Zou Futai
    Zhang Siyu
    Rao Weixiong
    CHINA COMMUNICATIONS, 2013, 10 (11) : 81 - 94
  • [46] Digital integrator for fast accurate measurement of magnetic flux by rotating coils
    Arpaia, Pasquale
    Masi, Alessandro
    Spiezia, Giovanni
    IEEE TRANSACTIONS ON INSTRUMENTATION AND MEASUREMENT, 2007, 56 (02) : 216 - 220
  • [47] NextGenMap: fast and accurate read mapping in highly polymorphic genomes
    Sedlazeck, Fritz J.
    Rescheneder, Philipp
    von Haeseler, Arndt
    BIOINFORMATICS, 2013, 29 (21) : 2790 - 2791
  • [48] CDFF: a fast and highly accurate method for recognizing traffic signs
    Lanmei Wang
    Lizhe Wang
    Yanbo Zhu
    Anliang Chu
    Guibao Wang
    Neural Computing and Applications, 2023, 35 : 643 - 662
  • [49] A Fast and Highly Accurate Carrier Acquisition for Deep Space Applications
    Wang, Le
    Wang, Zhugang
    Xiong, Weiming
    2012 5TH INTERNATIONAL CONGRESS ON IMAGE AND SIGNAL PROCESSING (CISP), 2012, : 1695 - 1698
  • [50] A fast and highly accurate numerical method for the evaluation of American options
    Allegretto, W
    Lin, YP
    Yang, HT
    DYNAMICS OF CONTINUOUS DISCRETE AND IMPULSIVE SYSTEMS-SERIES B-APPLICATIONS & ALGORITHMS, 2001, 8 (01): : 127 - 138