Cluster Ensemble with Link-Based Approach for Botnet Detection

被引:12
|
作者
Mai, Long [1 ]
Noh, Dong Kun [2 ]
机构
[1] Soongsil Univ, Dept Informat Commun Mat & Chem Convergence Techn, Seoul 06978, South Korea
[2] Soongsil Univ, Dept Software Convergence, Seoul 06978, South Korea
关键词
Cyber crime; Intrusion detection system; Network flow; Machine learning; Classification; Command and control; CLASSIFICATION;
D O I
10.1007/s10922-017-9436-x
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Botnet detection is one of the most imminent tasks for cyber security. Among popular botnet countermeasures, an intrusion detection system is the prominent mechanism. In the past, packet-based intrusion detection systems were popular. However, flow-based intrusion detection systems have been preferred in recent years due to their ability to adapt to modern high-speed networks. A collection of flows from an enterprise network usually contains both botnet traffic and normal traffic. To classify this traffic, supervised machine learning algorithms, i.e., classifications, have been applied and achieved a high accuracy. In an effort to improve the ability of intrusion detection systems against botnets, some studies have suggested partitioning flows into clusters before applying the classifications and this step could significantly reduce the complexity of a flow set. However, the instability of individual clustering algorithms is still a constraint for botnet detection.To overcome this bottleneck, we propose a novel method that combines individual partitions to become a strong learner through the use of a link-based algorithm. Our experiments show that our cluster ensemble model outperforms existing botnet detection mechanisms with a high reliability. We also determine the balance between accuracy and computer resources for botnet detection, and thereby propose a range for the maximum duration time of flows in botnet research.
引用
收藏
页码:616 / 639
页数:24
相关论文
共 50 条
  • [21] On measuring walking accessibility: A link-based utility approach
    Liang, Zheng
    Lo, Hong K.
    Ng, Ka Fai
    Axhausen, Kay W.
    TRANSPORTATION RESEARCH PART A-POLICY AND PRACTICE, 2025, 194
  • [22] A Fuzzy Link-Based Approach for XML Information Retrieval
    Mataoui, M'hamed
    Sebbak, Faouzi
    Benhammadi, Farid
    Bey, Kadda Beghdad
    2015 IEEE INTERNATIONAL CONFERENCE ON FUZZY SYSTEMS (FUZZ-IEEE 2015), 2015,
  • [23] A novel hybrid feature selection and ensemble-based machine learning approach for botnet detection
    Hossain, Md. Alamgir
    Islam, Md. Saiful
    SCIENTIFIC REPORTS, 2023, 13 (01)
  • [24] A novel hybrid feature selection and ensemble-based machine learning approach for botnet detection
    Md. Alamgir Hossain
    Md. Saiful Islam
    Scientific Reports, 13
  • [25] IoT Botnet Attacks Detection and Classification Based on Ensemble Learning
    Cao, Yongzhong
    Wang, Zhihui
    Ding, Hongwei
    Zhang, Jiale
    Li, Bin
    ARTIFICIAL INTELLIGENCE AND ROBOTICS, ISAIR 2023, 2024, 1998 : 45 - 55
  • [26] Link-based web spam detection using weight properties
    Kwang Leng Goh
    Ravi Kumar Patchmuthu
    Ashutosh Kumar Singh
    Journal of Intelligent Information Systems, 2014, 43 : 129 - 145
  • [27] Link-based web spam detection using weight properties
    Goh, Kwang Leng
    Patchmuthu, Ravi Kumar
    Singh, Ashutosh Kumar
    JOURNAL OF INTELLIGENT INFORMATION SYSTEMS, 2014, 43 (01) : 129 - 145
  • [28] An Improved Framework for Content- and Link-Based Web-Spam Detection: A Combined Approach
    Shahzad, Asim
    Nawi, Nazri Mohd
    Rehman, Muhammad Zubair
    Khan, Abdullah
    COMPLEXITY, 2021, 2021
  • [29] A Link-based Approach to Detect Media Bias in News Websites
    Aires, Victoria Patricia
    Nakamura, Fabiola G.
    Nakamura, Eduardo F.
    COMPANION OF THE WORLD WIDE WEB CONFERENCE (WWW 2019 ), 2019, : 742 - 745
  • [30] On Link-based Similarity Join
    Sun, Liwen
    Cheng, Reynold
    Li, Xiang
    Cheung, David W.
    Han, Jiawei
    PROCEEDINGS OF THE VLDB ENDOWMENT, 2011, 4 (11): : 714 - 725