Botnet Detection with Hybrid Analysis on Flow Based and Graph Based Features of Network Traffic

被引:10
|
作者
Shang, Yaoyao [1 ,2 ]
Yang, Shuangmao [2 ]
Wang, Wei [1 ,2 ]
机构
[1] Beijing Jiaotong Univ, Beijing Key Lab Secur & Privacy Intelligent Trans, 3 Shangyuancun, Beijing 100044, Peoples R China
[2] Sci & Technol Elect Informat Control Lab, Chengdu 610036, Sichuan, Peoples R China
来源
关键词
Botnet detection; Network traffic; Network security; AUDIT DATA STREAMS; BEHAVIOR; APPS;
D O I
10.1007/978-3-030-00009-7_55
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Botnets have become one of the most serious threats to cyber infrastructure. Many existing botnet detection approaches become invalid due to botnet structure sophistication or encryption of payload of the traffic. In this work, we propose an effective anomaly-based botnet detection method by hybrid analysis of flow based and graph-based features of network traffic. Frist, from network traffic we extract 15 statistical aggregated flow based features as well as 7 types of graph based features, such as in degree, out degree, in degree weight, out degree weight, node betweenness centrality, local clustering coefficient and PageRank. Second, we employ K-means, k-NN and One-class SVM to detect bots based on the hybrid analysis of these two types of features. Finally, we collect a large size of network traffic in real computing environment by implementing 5 different botnets including newly propagated Mirai and others like Athena and Black energy. The extensive experimental results show that our method based on the hybrid analysis is better than the method of individual analysis in terms of detection accuracy. It achieves the best performance with 96.62% of F-score. The experimental results also demonstrate the effectiveness of our method on the detection of novel botnets like Mirai, Athena and Black energy.
引用
收藏
页码:612 / 621
页数:10
相关论文
共 50 条
  • [31] Detecting domain-flux botnet based on DNS traffic features in managed network
    Dinh-Tu Truong
    Cheng, Guang
    SECURITY AND COMMUNICATION NETWORKS, 2016, 9 (14) : 2338 - 2347
  • [32] Encrypted Malware Traffic Detection via Graph-based Network Analysis
    Fu, Zhuoqun
    Liu, Mingxuan
    Qin, Yue
    Zhang, Jia
    Zou, Yuan
    Yin, Qilei
    Li, Qi
    Duan, Haixin
    PROCEEDINGS OF 25TH INTERNATIONAL SYMPOSIUM ON RESEARCH IN ATTACKS, INTRUSIONS AND DEFENSES, RAID 2022, 2022, : 495 - 509
  • [33] Analysis of Multi-Types of Flow Features Based on Hybrid Neural Network for Improving Network Anomaly Detection
    Ma, Chencheng
    Du, Xuehui
    Cao, Lifeng
    IEEE ACCESS, 2019, 7 : 148363 - 148380
  • [34] Traffic Flow Prediction Based on Multi-type Characteristic Hybrid Graph Neural Network
    Wang, Yuhang
    Gao, Hui
    ARTIFICIAL NEURAL NETWORKS AND MACHINE LEARNING, ICANN 2023, PT V, 2023, 14258 : 486 - 497
  • [35] Deeply fused flow and topology features for botnet detection based on a pretrained GCN
    Meng, Xiaoyuan
    Lang, Bo
    Yan, Yuhao
    Liu, Yanxi
    COMPUTER COMMUNICATIONS, 2025, 233
  • [36] Intrusion Detection Using Flow-Based Analysis of Network Traffic
    David, Jisa
    Thomas, Ciza
    ADVANCES IN NETWORKS AND COMMUNICATIONS, PT II, 2011, 132 : 391 - 399
  • [37] Accurate compressed traffic detection via traffic analysis using Graph Convolutional Network based on graph structure feature
    Fu, Nan
    Cheng, Guang
    Su, Xinyue
    COMPUTER COMMUNICATIONS, 2023, 207 : 128 - 139
  • [38] Detecting DGA-Based Botnet with DNS Traffic Analysis in Monitored Network
    Dinh-Tu Truong
    Cheng, Guang
    Jakalan, Ahmad
    Guo, Xiaojun
    Zhou, Aiping
    JOURNAL OF INTERNET TECHNOLOGY, 2016, 17 (02): : 217 - 230
  • [39] Botnet-based IoT network traffic analysis using deep learning
    Singh, N. Joychandra
    Hoque, Nazrul
    Singh, Kh. Robindro
    Bhattacharyya, Dhruba K.
    SECURITY AND PRIVACY, 2024, 7 (02)
  • [40] Fast-flux Botnet Detection Method Based on Spatiotemporal Feature of Network Traffic
    Niu Weina
    Jiang Tianyu
    Zhang Xiaosong
    Xie Jiao
    Zhang Junzhe
    Zhao Zhenfei
    JOURNAL OF ELECTRONICS & INFORMATION TECHNOLOGY, 2020, 42 (08) : 1872 - 1880