A Combined Fusion and Data Mining Framework for the Detection of Botnets

被引:1
|
作者
Kiayias, Aggelos [1 ]
Neumann, Justin [1 ]
Walluck, David [1 ]
McCusker, Owen [2 ]
机构
[1] Univ Connecticut, Dept Comp Sci & Engn, Storrs, CT 06269 USA
[2] Sonalysts Inc, Waterbury, CT 06385 USA
关键词
botnets; crimeware; distributed threat; data fusion; data mining; distributed detection model; profile; hyperplane; network behavior analyzer; threat-centricity; SYSTEM;
D O I
10.1109/CATCH.2009.9
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
This paper describes a combined fusion and mining framework applied to the detection of stealthy botnets. The framework leverages a fusion engine that tracks hosts through the use of feature-based profiles generated front multiple network sensor types. These profiles are classified and correlated based oil a set of known host profiles, e.g., web servers, mail servers, and hot behavioral characteristics. A mining engine discovers emergent threat profiles and delivers them to the fusion engine for processing. We describe the distributed nature of botnets and how they are created and managed. We then describe a combined fusion and mining model that builds orgy recent work in the cyber security domain. Pie framework tie present employs an adaptive fusion system driven by a mining system focused oil the discovery of new threats. We conclude with a discussion of experimental results, deployment issues, anal a summary of our arguments.
引用
收藏
页码:273 / +
页数:3
相关论文
共 50 条
  • [41] An alert data mining framework for network-based intrusion detection system
    Shin, MS
    Jeong, KJ
    INFORMATION SECURITY APPLICATIONS, 2006, 3786 : 38 - 53
  • [42] An Intrusion Detection Framework Based on Hybrid Multi-Level Data Mining
    Haipeng Yao
    Qiyi Wang
    Luyao Wang
    Peiying Zhang
    Maozhen Li
    Yunjie Liu
    International Journal of Parallel Programming, 2019, 47 : 740 - 758
  • [43] Image Pattern Recognition Combined With Data Mining for Diagnosis and Detection of Myocardial Infarction
    Tang, Xiaoqiang
    Zhang, Ming
    Shi, Haifeng
    Pan, Changjie
    IEEE ACCESS, 2020, 8 : 146085 - 146092
  • [44] Combined Mathematical Morphology and Data Mining Based High Impedance Fault Detection
    Sekar, Kavaskar
    Mohanty, Nalin Kant
    FIRST INTERNATIONAL CONFERENCE ON POWER ENGINEERING COMPUTING AND CONTROL (PECCON-2017 ), 2017, 117 : 417 - 423
  • [45] Data Dimensionality Reduction Framework for Data Mining
    Danubianu, M.
    Pentiuc, St Gh.
    ELEKTRONIKA IR ELEKTROTECHNIKA, 2013, 19 (04) : 87 - 90
  • [46] Distributed video data fusion and mining
    Chang, EY
    Wang, YF
    Rodoplu, V
    SENSORS, AND COMMAND, CONTROL, COMMUNICATIONS, AND INTELLIGENCE(C31) TECHNOLOGIES FOR HOMELAND SECURITY AND HOMELAND DEFENSE III, PTS 1 AND 2, 2004, 5403 : 222 - 233
  • [47] Detection DNS Tunneling Botnets
    Savenko, Bohdan
    Lysenko, Sergii
    Bobrovnikova, Kira
    Savenko, Oleg
    Markowsky, George
    PROCEEDINGS OF THE THE 11TH IEEE INTERNATIONAL CONFERENCE ON INTELLIGENT DATA ACQUISITION AND ADVANCED COMPUTING SYSTEMS: TECHNOLOGY AND APPLICATIONS (IDAACS'2021), VOL 1, 2021, : 64 - 69
  • [48] Combined Forest: a New Supervised Approach for a Machine-Learning-based Botnets Detection
    Maudoux, Christophe
    Boumerdassi, Selma
    Barcello, Alex
    Renault, Eric
    2021 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2021,
  • [49] Tensor Framework and Combined Symmetry for Hypertext Mining
    Saha, Suman
    Murthy, C. A.
    Pal, Sankar K.
    FUNDAMENTA INFORMATICAE, 2009, 97 (1-2) : 215 - 234
  • [50] MDFD: A multi-source data fusion detection framework for Sybil attack detection in VANETs
    Chen, Ye
    Lai, Yingxu
    Zhang, Zhaoyi
    Li, Hanmei
    Wang, Yuhang
    COMPUTER NETWORKS, 2023, 224