Cluster Ensemble with Link-Based Approach for Botnet Detection

被引:12
|
作者
Mai, Long [1 ]
Noh, Dong Kun [2 ]
机构
[1] Soongsil Univ, Dept Informat Commun Mat & Chem Convergence Techn, Seoul 06978, South Korea
[2] Soongsil Univ, Dept Software Convergence, Seoul 06978, South Korea
关键词
Cyber crime; Intrusion detection system; Network flow; Machine learning; Classification; Command and control; CLASSIFICATION;
D O I
10.1007/s10922-017-9436-x
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Botnet detection is one of the most imminent tasks for cyber security. Among popular botnet countermeasures, an intrusion detection system is the prominent mechanism. In the past, packet-based intrusion detection systems were popular. However, flow-based intrusion detection systems have been preferred in recent years due to their ability to adapt to modern high-speed networks. A collection of flows from an enterprise network usually contains both botnet traffic and normal traffic. To classify this traffic, supervised machine learning algorithms, i.e., classifications, have been applied and achieved a high accuracy. In an effort to improve the ability of intrusion detection systems against botnets, some studies have suggested partitioning flows into clusters before applying the classifications and this step could significantly reduce the complexity of a flow set. However, the instability of individual clustering algorithms is still a constraint for botnet detection.To overcome this bottleneck, we propose a novel method that combines individual partitions to become a strong learner through the use of a link-based algorithm. Our experiments show that our cluster ensemble model outperforms existing botnet detection mechanisms with a high reliability. We also determine the balance between accuracy and computer resources for botnet detection, and thereby propose a range for the maximum duration time of flows in botnet research.
引用
收藏
页码:616 / 639
页数:24
相关论文
共 50 条
  • [41] LINK INTEGRATOR A Link-based Data Integration Architecture
    Lopes, Pedro
    Arrais, Joel
    Oliveira, Jose Luis
    KDIR 2009: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON KNOWLEDGE DISCOVERY AND INFORMATION RETRIEVAL, 2009, : 274 - 277
  • [42] Link-based service customization for NGN
    Thanh, Vu Truong
    Urano, Yoshiyori
    10TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY, VOLS I-III: INNOVATIONS TOWARD FUTURE NETWORKS AND SERVICES, 2008, : 57 - 60
  • [43] Link-based collection fusion strategy
    Sch. of Comp. and Info. Systems, Univ. Sunderland, St Peter's C., Sunderland, United Kingdom
    Inf. Process. Manage., 5 (691-711):
  • [44] An Approach for Detection of Botnet Based on Machine Learning Classifier
    Tikekar P.C.
    Sherekar S.S.
    Kumar J.
    SN Computer Science, 5 (3)
  • [45] Link community detection based on ensemble learning
    Liu, Zhihua
    Wang, Hongmei
    Wang, Guishen
    Zhou, Yu
    MODERN PHYSICS LETTERS B, 2020, 34 (27):
  • [46] Evaluating Link-based Recommendations for Wikipedia
    Schwarzer, Malte
    Schubotz, Moritz
    Meuschke, Norman
    Breitinger, Corinna
    Markl, Volker
    Gipp, Bela
    2016 IEEE/ACM JOINT CONFERENCE ON DIGITAL LIBRARIES (JCDL), 2016, : 191 - 200
  • [47] A link-based collection fusion strategy
    Salampasis, M
    Tait, J
    INFORMATION PROCESSING & MANAGEMENT, 1999, 35 (05) : 691 - 711
  • [48] A link-based ranking model for services
    Constantin, Camelia
    Amann, Bernd
    Gross-Amblard, David
    ON THE MOVE TO MEANINGFUL INTERNET SYSTEMS 2006: COOPIS, DOA, GADA, AND ODBAS, PT 1, PROCEEDINGS, 2006, 4275 : 327 - 344
  • [49] A link-based rank of postings in newsgroup
    Liu, Hongbo
    Yang, Jiahai
    Wang, Jiaxin
    Zhang, Yu
    MACHINE LEARNING AND DATA MINING IN PATTERN RECOGNITION, PROCEEDINGS, 2007, 4571 : 392 - +
  • [50] Data Randomization and Cluster-Based Partitioning for Botnet Intrusion Detection
    Al-Jarrah, Omar Y.
    Alhussein, Omar
    Yoo, Paul D.
    Muhaidat, Sami
    Taha, Kamal
    Kim, Kwangjo
    IEEE TRANSACTIONS ON CYBERNETICS, 2016, 46 (08) : 1796 - 1806