A novel Machine Learning-based approach for the detection of SSH botnet infection

被引:15
|
作者
Martinez Garre, Jose Tomas [1 ]
Gil Perez, Manuel [1 ]
Ruiz-Martinez, Antonio [1 ]
机构
[1] Univ Murcia, Dept Informat & Commun Engn, Murcia 30100, Spain
基金
欧盟地平线“2020”;
关键词
Botnet; Machine learning; Zero-day malware; Honeypot; High interaction;
D O I
10.1016/j.future.2020.09.004
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Botnets are causing severe damages to users, companies, and governments through information theft, abuse of online services, DDoS attacks, etc. Although significant research is being made to detect them and mitigate their effect, they are exponentially increasing due to new zero-day attacks, a variation of their behavior, and obfuscation techniques. High Interaction Honeypots (HIH) are the only honeypots able to capture attacks and log all the information generated by attackers when setting up a botnet. The data generated is being processed using Machine Learning (ML) techniques for detection since they can detect hidden patterns. However, so far, research has been focused on intermediate phases of the botnet's life cycle during operation, underestimating the initial phase of infection. To the best of our knowledge, this is the first solution in the infection phase of SSH-based botnets. Therefore, we have designed an approach based on an SSH-based HIH to generate a dataset consisting of executed commands and network information. Herein, we have applied ML techniques for the development of a real-time detection model. This approach reached a very high level of prediction and zero false negatives. Indeed, our system detected all known and unknown SSH sessions intended to infect our honeypots. Thus, our research has demonstrated that new SSH infections can be detected through ML techniques. (C) 2020 Elsevier B.V. All rights reserved.
引用
收藏
页码:387 / 396
页数:10
相关论文
共 50 条
  • [21] Deep learning-based classification model for botnet attack detection
    Ahmed, Abdulghani Ali
    Jabbar, Waheb A.
    Sadiq, Ali Safaa
    Patel, Hiran
    JOURNAL OF AMBIENT INTELLIGENCE AND HUMANIZED COMPUTING, 2020, 13 (7) : 3457 - 3466
  • [22] Deep Learning-based Intrusion Detection: A Novel Approach for Identifying Brute-Force Attacks on FTP and SSH Protocol
    Alotibi, Noura
    Alshammari, Majid
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2023, 14 (06) : 107 - 111
  • [23] A novel deep learning-based approach for malware detection
    Shaukat, Kamran
    Luo, Suhuai
    Varadharajan, Vijay
    ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2023, 122
  • [24] Oscillation Detection in Process Industries by a Machine Learning-Based Approach
    Dambros, Jonathan W., V
    Trierweiler, Jorge O.
    Farenzena, Marcelo
    Kloft, Marius
    INDUSTRIAL & ENGINEERING CHEMISTRY RESEARCH, 2019, 58 (31) : 14180 - 14192
  • [25] A Machine Learning-Based Approach for Fault Detection in Power Systems
    Ilius, Pathan
    Almuhaini, Mohammad
    Javaid, Muhammad
    Abido, Mohammad
    ENGINEERING TECHNOLOGY & APPLIED SCIENCE RESEARCH, 2023, 13 (04) : 11216 - 11221
  • [26] A machine learning-based approach for mercury detection in marine waters
    Piccialli, Francesco
    Giampaolo, Fabio
    Di Cola, Vincenzo Schiano
    Gatta, Federico
    Chiaro, Diletta
    Prezioso, Edoardo
    Izzo, Stefano
    Cuomo, Salvatore
    2022 IEEE INTERNATIONAL CONFERENCE ON DATA MINING WORKSHOPS, ICDMW, 2022, : 527 - 536
  • [27] Code Smell Detection: Towards a Machine Learning-based Approach
    Fontana, Francesca Arcelli
    Zanoni, Marco
    Marino, Alessandro
    Mantyla, Mika V.
    2013 29TH IEEE INTERNATIONAL CONFERENCE ON SOFTWARE MAINTENANCE (ICSM), 2013, : 396 - 399
  • [28] The Role of Machine Learning in Botnet Detection
    Miller, Sean
    Busby-Earle, Curtis
    2016 11TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2016, : 359 - 364
  • [29] Botnet Detection using Machine Learning
    Haq, Shamsul
    Singh, Yashwant
    2018 FIFTH INTERNATIONAL CONFERENCE ON PARALLEL, DISTRIBUTED AND GRID COMPUTING (IEEE PDGC), 2018, : 240 - 245
  • [30] Dimensionality Reduction for Machine Learning Based IoT Botnet Detection
    Bahsi, Hayretdin
    Nomm, Sven
    La Torre, Fabio Benedetto
    2018 15TH INTERNATIONAL CONFERENCE ON CONTROL, AUTOMATION, ROBOTICS AND VISION (ICARCV), 2018, : 1857 - 1862