Botnet Detection with Hybrid Analysis on Flow Based and Graph Based Features of Network Traffic

被引:10
|
作者
Shang, Yaoyao [1 ,2 ]
Yang, Shuangmao [2 ]
Wang, Wei [1 ,2 ]
机构
[1] Beijing Jiaotong Univ, Beijing Key Lab Secur & Privacy Intelligent Trans, 3 Shangyuancun, Beijing 100044, Peoples R China
[2] Sci & Technol Elect Informat Control Lab, Chengdu 610036, Sichuan, Peoples R China
来源
关键词
Botnet detection; Network traffic; Network security; AUDIT DATA STREAMS; BEHAVIOR; APPS;
D O I
10.1007/978-3-030-00009-7_55
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Botnets have become one of the most serious threats to cyber infrastructure. Many existing botnet detection approaches become invalid due to botnet structure sophistication or encryption of payload of the traffic. In this work, we propose an effective anomaly-based botnet detection method by hybrid analysis of flow based and graph-based features of network traffic. Frist, from network traffic we extract 15 statistical aggregated flow based features as well as 7 types of graph based features, such as in degree, out degree, in degree weight, out degree weight, node betweenness centrality, local clustering coefficient and PageRank. Second, we employ K-means, k-NN and One-class SVM to detect bots based on the hybrid analysis of these two types of features. Finally, we collect a large size of network traffic in real computing environment by implementing 5 different botnets including newly propagated Mirai and others like Athena and Black energy. The extensive experimental results show that our method based on the hybrid analysis is better than the method of individual analysis in terms of detection accuracy. It achieves the best performance with 96.62% of F-score. The experimental results also demonstrate the effectiveness of our method on the detection of novel botnets like Mirai, Athena and Black energy.
引用
收藏
页码:612 / 621
页数:10
相关论文
共 50 条
  • [1] BotMark: Automated botnet detection with hybrid analysis of flow-based and graph-based traffic behaviors
    Wang, Wei
    Shang, Yaoyao
    He, Yongzhong
    Li, Yidong
    Liu, Jiqiang
    INFORMATION SCIENCES, 2020, 511 : 284 - 296
  • [2] Hybrid Botnet Detection Based on Host and Network Analysis
    Almutairi, Suzan
    Mahfoudh, Saoucene
    Almutairi, Sultan
    Alowibdi, Jalal S.
    JOURNAL OF COMPUTER NETWORKS AND COMMUNICATIONS, 2020, 2020
  • [3] Peer to Peer Botnet Detection Based on Network Traffic Analysis
    Almutairi, Suzan
    Mahfoudh, Saoucene
    Alowibdi, Jalal S.
    2016 8TH IFIP INTERNATIONAL CONFERENCE ON NEW TECHNOLOGIES, MOBILITY AND SECURITY (NTMS), 2016,
  • [4] Botnet detection based on traffic behavior analysis and flow intervals
    Zhao, David
    Traore, Issa
    Sayed, Bassam
    Lu, Wei
    Saad, Sherif
    Ghorbani, Ali
    Garant, Dan
    COMPUTERS & SECURITY, 2013, 39 : 2 - 16
  • [5] Smart Approach for Botnet Detection Based on Network Traffic Analysis
    Obeidat, Alaa
    Yaqbeh, Rola
    JOURNAL OF ELECTRICAL AND COMPUTER ENGINEERING, 2022, 2022
  • [6] Botnet detection based on network flow analysis using inverse statistics
    Lopes, Daniele A. G.
    Marotta, Marcelo A.
    Ladeira, Marcelo
    Gondim, Joao J. C.
    2022 17TH IBERIAN CONFERENCE ON INFORMATION SYSTEMS AND TECHNOLOGIES (CISTI), 2022,
  • [7] Graph based encrypted malicious traffic detection with hybrid analysis of multi-view features
    Hong, Yueping
    Li, Qi
    Yang, Yanqing
    Shen, Meng
    INFORMATION SCIENCES, 2023, 644
  • [8] Flow Based Botnet Traffic Detection Using Machine Learning
    Gahelot, Parul
    Dayal, Neelam
    PROCEEDINGS OF ICETIT 2019: EMERGING TRENDS IN INFORMATION TECHNOLOGY, 2020, 605 : 418 - 426
  • [9] Botnet Detection Based on Analysis of Mail Flow
    Wang Chun-dong
    Li Ting
    Wang Huai-bin
    PROCEEDINGS OF THE 2009 2ND INTERNATIONAL CONFERENCE ON BIOMEDICAL ENGINEERING AND INFORMATICS, VOLS 1-4, 2009, : 2067 - 2070
  • [10] Behaviour based botnet detection with traffic analysis and flow interavals using PSO and SVM
    Kapre, Amruta
    Padmavathi, B.
    2017 INTERNATIONAL CONFERENCE ON INTELLIGENT COMPUTING AND CONTROL SYSTEMS (ICICCS), 2017, : 718 - 722