Cluster Ensemble with Link-Based Approach for Botnet Detection

被引:12
|
作者
Mai, Long [1 ]
Noh, Dong Kun [2 ]
机构
[1] Soongsil Univ, Dept Informat Commun Mat & Chem Convergence Techn, Seoul 06978, South Korea
[2] Soongsil Univ, Dept Software Convergence, Seoul 06978, South Korea
关键词
Cyber crime; Intrusion detection system; Network flow; Machine learning; Classification; Command and control; CLASSIFICATION;
D O I
10.1007/s10922-017-9436-x
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Botnet detection is one of the most imminent tasks for cyber security. Among popular botnet countermeasures, an intrusion detection system is the prominent mechanism. In the past, packet-based intrusion detection systems were popular. However, flow-based intrusion detection systems have been preferred in recent years due to their ability to adapt to modern high-speed networks. A collection of flows from an enterprise network usually contains both botnet traffic and normal traffic. To classify this traffic, supervised machine learning algorithms, i.e., classifications, have been applied and achieved a high accuracy. In an effort to improve the ability of intrusion detection systems against botnets, some studies have suggested partitioning flows into clusters before applying the classifications and this step could significantly reduce the complexity of a flow set. However, the instability of individual clustering algorithms is still a constraint for botnet detection.To overcome this bottleneck, we propose a novel method that combines individual partitions to become a strong learner through the use of a link-based algorithm. Our experiments show that our cluster ensemble model outperforms existing botnet detection mechanisms with a high reliability. We also determine the balance between accuracy and computer resources for botnet detection, and thereby propose a range for the maximum duration time of flows in botnet research.
引用
收藏
页码:616 / 639
页数:24
相关论文
共 50 条
  • [1] Cluster Ensemble with Link-Based Approach for Botnet Detection
    Long Mai
    Dong Kun Noh
    Journal of Network and Systems Management, 2018, 26 : 616 - 639
  • [2] A Link-Based Approach to the Cluster Ensemble Problem
    Iam-On, Natthakan
    Boongoen, Tossapon
    Garrett, Simon
    Price, Chris
    IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2011, 33 (12) : 2396 - 2409
  • [3] A Link-Based Cluster Ensemble Approach for Categorical Data Clustering
    Iam-On, Natthakan
    Boongoen, Tossapon
    Garrett, Simon
    Price, Chris
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2012, 24 (03) : 413 - 425
  • [4] High-performance link-based cluster ensemble approach for categorical data clustering
    Yuvaraj, N.
    Dhas, C. Suresh Ghana
    JOURNAL OF SUPERCOMPUTING, 2020, 76 (06): : 4556 - 4579
  • [5] High-performance link-based cluster ensemble approach for categorical data clustering
    N. Yuvaraj
    C. Suresh Ghana Dhas
    The Journal of Supercomputing, 2020, 76 : 4556 - 4579
  • [6] A link-based fuzzy clustering ensemble
    Yang, Yan
    Feng, Chen-Fei
    Jia, Zhen
    Wang, Hong-Jun
    Dianzi Keji Daxue Xuebao/Journal of the University of Electronic Science and Technology of China, 2014, 43 (06): : 887 - 892
  • [7] Improved Link-Based Cluster Ensembles
    Iam-On, Natthakan
    Boongoen, Tossapon
    2012 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2012,
  • [8] Diversity-driven generation of link-based cluster ensemble and application to data classification
    Iam-On, Natthakan
    Boongoen, Tossapon
    EXPERT SYSTEMS WITH APPLICATIONS, 2015, 42 (21) : 8259 - 8273
  • [9] LCE: a link-based cluster ensemble method for improved gene expression data analysis
    Iam-on, Natthakan
    Boongoen, Tossapon
    Garrett, Simon
    BIOINFORMATICS, 2010, 26 (12) : 1513 - 1519
  • [10] LinkCluE: A MATLAB Package for Link-Based Cluster Ensembles
    Iam-on, Natthakan
    Garrett, Simon
    JOURNAL OF STATISTICAL SOFTWARE, 2010, 36 (09): : 1 - 36