A Combined Fusion and Data Mining Framework for the Detection of Botnets

被引:1
|
作者
Kiayias, Aggelos [1 ]
Neumann, Justin [1 ]
Walluck, David [1 ]
McCusker, Owen [2 ]
机构
[1] Univ Connecticut, Dept Comp Sci & Engn, Storrs, CT 06269 USA
[2] Sonalysts Inc, Waterbury, CT 06385 USA
关键词
botnets; crimeware; distributed threat; data fusion; data mining; distributed detection model; profile; hyperplane; network behavior analyzer; threat-centricity; SYSTEM;
D O I
10.1109/CATCH.2009.9
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
This paper describes a combined fusion and mining framework applied to the detection of stealthy botnets. The framework leverages a fusion engine that tracks hosts through the use of feature-based profiles generated front multiple network sensor types. These profiles are classified and correlated based oil a set of known host profiles, e.g., web servers, mail servers, and hot behavioral characteristics. A mining engine discovers emergent threat profiles and delivers them to the fusion engine for processing. We describe the distributed nature of botnets and how they are created and managed. We then describe a combined fusion and mining model that builds orgy recent work in the cyber security domain. Pie framework tie present employs an adaptive fusion system driven by a mining system focused oil the discovery of new threats. We conclude with a discussion of experimental results, deployment issues, anal a summary of our arguments.
引用
收藏
页码:273 / +
页数:3
相关论文
共 50 条
  • [1] An adaptive framework for the detection of novel botnets
    Cid-Fuentes, Javier Alvarez
    Szabo, Claudia
    Falkner, Katrina
    COMPUTERS & SECURITY, 2018, 79 : 148 - 161
  • [2] Botnets: A Heuristic-Based Detection Framework
    Mendonca, Luis
    Santos, Henrique
    PROCEEDINGS OF THE FIFTH INTERNATIONAL CONFERENCE ON SECURITY OF INFORMATION AND NETWORKS, 2012, : 33 - 40
  • [3] Combined data mining approach for intrusion detection
    Zurutuza, U.
    Uribeetxeberria, R.
    Azketa, E.
    Gil, G.
    Lizarraga, J.
    Fernandez, M.
    SECRYPT 2007: PROCEEDINGS OF THE SECOND INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, 2007, : 67 - 73
  • [4] Data Fusion Framework for Sand Detection in Pipelines
    Abdelgawad, A.
    Merhi, Zaher
    Elgamel, Mohamed
    Bayoumi, Magdy
    Zaki, Amal
    ISCAS: 2009 IEEE INTERNATIONAL SYMPOSIUM ON CIRCUITS AND SYSTEMS, VOLS 1-5, 2009, : 2173 - +
  • [5] Data Mining and Fusion Framework for In-Home Monitoring Applications
    Ekerete, Idongesit
    Garcia-Constantino, Matias
    Nugent, Christopher
    Mccullagh, Paul
    Mclaughlin, James
    Boukallel, Mehdi
    SENSORS, 2023, 23 (21)
  • [6] A data fusion and data mining method for ship supervision and fault detection
    Tang, TH
    Dou, JS
    Yao, G
    Proceedings of the Eighth IASTED International Conference on Artificial Intelligence and Soft Computing, 2004, : 203 - 208
  • [7] Data mining framework for building intrusion detection models
    Columbia Univ, New York, United States
    Proc IEEE Comput Soc Symp Res Secur Privacy, (120-132):
  • [8] An efficient framework for intrusion detection based on data mining
    Li, Weidong
    Zhang, Kejun
    Li, Boqun
    Yang, Bingru
    2005 ICSC CONGRESS ON COMPUTATIONAL INTELLIGENCE METHODS AND APPLICATIONS (CIMA 2005), 2005, : 55 - 58
  • [9] A data mining framework for building intrusion detection models
    Lee, W
    Stolfo, SJ
    Mok, KW
    PROCEEDINGS OF THE 1999 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, 1999, : 120 - 132
  • [10] Mining Botnets and Their Evolution Patterns
    Jaehoon Choi
    Jaewoo Kang
    Jinseung Lee
    Chihwan Song
    Qingsong Jin
    Sunwon Lee
    Jinsun Uh
    Journal of Computer Science & Technology, 2013, 28 (04) : 605 - 615