Botnet Detection with Hybrid Analysis on Flow Based and Graph Based Features of Network Traffic

被引:10
|
作者
Shang, Yaoyao [1 ,2 ]
Yang, Shuangmao [2 ]
Wang, Wei [1 ,2 ]
机构
[1] Beijing Jiaotong Univ, Beijing Key Lab Secur & Privacy Intelligent Trans, 3 Shangyuancun, Beijing 100044, Peoples R China
[2] Sci & Technol Elect Informat Control Lab, Chengdu 610036, Sichuan, Peoples R China
来源
关键词
Botnet detection; Network traffic; Network security; AUDIT DATA STREAMS; BEHAVIOR; APPS;
D O I
10.1007/978-3-030-00009-7_55
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Botnets have become one of the most serious threats to cyber infrastructure. Many existing botnet detection approaches become invalid due to botnet structure sophistication or encryption of payload of the traffic. In this work, we propose an effective anomaly-based botnet detection method by hybrid analysis of flow based and graph-based features of network traffic. Frist, from network traffic we extract 15 statistical aggregated flow based features as well as 7 types of graph based features, such as in degree, out degree, in degree weight, out degree weight, node betweenness centrality, local clustering coefficient and PageRank. Second, we employ K-means, k-NN and One-class SVM to detect bots based on the hybrid analysis of these two types of features. Finally, we collect a large size of network traffic in real computing environment by implementing 5 different botnets including newly propagated Mirai and others like Athena and Black energy. The extensive experimental results show that our method based on the hybrid analysis is better than the method of individual analysis in terms of detection accuracy. It achieves the best performance with 96.62% of F-score. The experimental results also demonstrate the effectiveness of our method on the detection of novel botnets like Mirai, Athena and Black energy.
引用
收藏
页码:612 / 621
页数:10
相关论文
共 50 条
  • [41] P2P Botnet Detection Method Based on Graph Neural Network
    Lin H.
    Zhang Y.
    Guo N.
    Chen L.
    Gongcheng Kexue Yu Jishu/Advanced Engineering Sciences, 2022, 54 (02): : 65 - 72
  • [42] Deep Graph Embedding for IoT Botnet Traffic Detection
    Zhang, Bonan
    Li, Jingjin
    Ward, Lindsay
    Zhang, Ying
    Chen, Chao
    Zhang, Jun
    Security and Communication Networks, 2023, 2023
  • [43] Fast-flux Botnet Detection Method Based on Spatiotemporal Feature of Network Traffic
    Niu W.
    Jiang T.
    Zhang X.
    Xie J.
    Zhang J.
    Zhao Z.
    Dianzi Yu Xinxi Xuebao/Journal of Electronics and Information Technology, 2020, 42 (08): : 1872 - 1880
  • [44] Classification of botnet families based on features self-learning under Network Traffic Censorship
    Zhou, Zhihong
    Yao, Lihong
    Hu, Bin
    Li, Jianhua
    Wang, Chen
    Wang, Zhenglong
    2018 THIRD INTERNATIONAL CONFERENCE ON SECURITY OF SMART CITIES, INDUSTRIAL CONTROL SYSTEM AND COMMUNICATIONS (SSIC), 2018,
  • [45] Anomaly detection of traffic session based on graph neural network
    Du Peng
    Peng Cheng-Wei
    Xiang Peng
    Li Qing-Shan
    PROCEEDINGS OF THE 2022 INTERNATIONAL CONFERENCE ON CYBER SECURITY, CSW 2022, 2022, : 1 - 9
  • [46] Botnet Detection Based on Genetic Neural Network
    Yin, Chunyong
    Awlla, Ardalan Husin
    Yin, Zhichao
    Wang, Jin
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2015, 9 (11): : 97 - 104
  • [47] A Conformalized Density-based Clustering Analysis of Malicious Traffic for Botnet Detection
    Kiani, Bahareh Mohammadi
    CONFORMAL AND PROBABILISTIC PREDICTION AND APPLICATIONS, VOL 128, 2020, 128 : 244 - 256
  • [48] Network Flow based IoT Botnet Attack Detection using Deep Learning
    Sriram, S.
    Vinayakumar, R.
    Alazab, Mamoun
    Soman, K. P.
    IEEE INFOCOM 2020 - IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (INFOCOM WKSHPS), 2020, : 189 - 194
  • [49] Botnet detection based on generative adversarial network
    Zou, Futai
    Tan, Yue
    Wang, Lin
    Jiang, Yongkang
    Tongxin Xuebao/Journal on Communications, 2021, 42 (07): : 95 - 106
  • [50] Traffic Flow Prediction Method Based on Fast Statistics of Traffic Flow and Graph Convolutional Network
    Jiang, Dan
    Hou, Qun
    Liu, Xin
    Gao, Shidi
    2023 IEEE 8th International Conference on Intelligent Transportation Engineering, ICITE 2023, 2023, : 54 - 59