Cluster Ensemble with Link-Based Approach for Botnet Detection

被引:12
|
作者
Mai, Long [1 ]
Noh, Dong Kun [2 ]
机构
[1] Soongsil Univ, Dept Informat Commun Mat & Chem Convergence Techn, Seoul 06978, South Korea
[2] Soongsil Univ, Dept Software Convergence, Seoul 06978, South Korea
关键词
Cyber crime; Intrusion detection system; Network flow; Machine learning; Classification; Command and control; CLASSIFICATION;
D O I
10.1007/s10922-017-9436-x
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Botnet detection is one of the most imminent tasks for cyber security. Among popular botnet countermeasures, an intrusion detection system is the prominent mechanism. In the past, packet-based intrusion detection systems were popular. However, flow-based intrusion detection systems have been preferred in recent years due to their ability to adapt to modern high-speed networks. A collection of flows from an enterprise network usually contains both botnet traffic and normal traffic. To classify this traffic, supervised machine learning algorithms, i.e., classifications, have been applied and achieved a high accuracy. In an effort to improve the ability of intrusion detection systems against botnets, some studies have suggested partitioning flows into clusters before applying the classifications and this step could significantly reduce the complexity of a flow set. However, the instability of individual clustering algorithms is still a constraint for botnet detection.To overcome this bottleneck, we propose a novel method that combines individual partitions to become a strong learner through the use of a link-based algorithm. Our experiments show that our cluster ensemble model outperforms existing botnet detection mechanisms with a high reliability. We also determine the balance between accuracy and computer resources for botnet detection, and thereby propose a range for the maximum duration time of flows in botnet research.
引用
收藏
页码:616 / 639
页数:24
相关论文
共 50 条
  • [31] AN APPROACH FOR HOST BASED BOTNET DETECTION SYSTEM
    Aleksieva, Yulia
    Valchanov, Hristo
    Aleksieva, Veneta
    2019 16TH CONFERENCE ON ELECTRICAL MACHINES, DRIVES AND POWER SYSTEMS (ELMA), 2019,
  • [32] A Link-Based Similarity for Improving Community Detection Based on Label Propagation Algorithm
    Berahmand, Kamal
    Bouyer, Asgarali
    JOURNAL OF SYSTEMS SCIENCE & COMPLEXITY, 2019, 32 (03) : 737 - 758
  • [33] A Link-Based Similarity for Improving Community Detection Based on Label Propagation Algorithm
    Kamal Berahmand
    Asgarali Bouyer
    Journal of Systems Science and Complexity, 2019, 32 : 737 - 758
  • [34] An Ensemble Machine Learning Botnet Detection Framework Based on Noise Filtering
    Liu, Tzong-Jye
    Lin, Tze-Shiun
    Chen, Ching-Wen
    JOURNAL OF INTERNET TECHNOLOGY, 2021, 22 (06): : 1347 - 1357
  • [35] LOADED: Link-based outlier and anomaly detection in evolving data sets
    Ghoting, A
    Otey, ME
    Parthasarathy, S
    FOURTH IEEE INTERNATIONAL CONFERENCE ON DATA MINING, PROCEEDINGS, 2004, : 387 - 390
  • [36] A Link-Based Similarity for Improving Community Detection Based on Label Propagation Algorithm
    BERAHMAND Kamal
    BOUYER Asgarali
    Journal of Systems Science & Complexity, 2019, 32 (03) : 737 - 758
  • [37] Web Spam Detection using Link-based Ant Colony Optimization
    Taweesiriwate, Apichat
    Manaskasemsak, Bundit
    Rungsawang, Arnon
    2012 IEEE 26TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS (AINA), 2012, : 868 - 873
  • [38] Link-based approach to study scientific software usage: the case of VOSviewer
    Orduna-Malea, Enrique
    Costas, Rodrigo
    SCIENTOMETRICS, 2021, 126 (09) : 8153 - 8186
  • [39] Link-based approach to study scientific software usage: the case of VOSviewer
    Enrique Orduña-Malea
    Rodrigo Costas
    Scientometrics, 2021, 126 : 8153 - 8186
  • [40] Link-Based Classification for MultiRelational Database
    Mistry, Urvashi
    Thakkar, Amit R.
    2014 RECENT ADVANCES AND INNOVATIONS IN ENGINEERING (ICRAIE), 2014,