返回
A Deep Learning Approach for Botnet Detection Using Raw Network Traffic Data
DOI:10.1007/s10922-022-09655-7.png)
摘要
En 中文
Botnets are considered to be one of the most serious cybersecurity threats in recent years. While botnets have been widely studied, they are constantly evolving, becoming more sophisticated and robust against detection systems. Current approaches of botnet detection commonly use manual feature engineering or analyze packet contents violating the privacy of users. Although some studies use raw packet bytes for botnet detection, this approach is rarely reported for the comprehensive ISCX botnet dataset. In this paper, we propose a deep learning-based network traffic analyzer for botnet detection, which automatically extracts the convenient features from raw packet data. The raw data is extracted only from the headers of the first few packets in a flow. The proposed approach lifts the costs of manual feature engineering, preserves user privacy, and offers early detection of malicious traffic. We further enrich the raw data with temporal information of packets and field correlations, to construct four different flows signatures. The evaluations are performed with the ISCX botnet dataset, which contains new botnet types in its test data. We show the effectiveness of botnet detection based on raw data, by comparing the performance of the proposed approach against several feature-based methods. The evaluation results also show that the proposed approach outperforms several state-of-the-art studies based on the same dataset, and provides high accuracy of 97.13% in classifying network traffic.
Keyword:
Botnet detection
Network traffic classification
Raw packets flow
Deep learning
Temporal information
Correlation
期刊
IF:
3.9
论文数:
1.0K
被引数:
1.3K
机构
引用论文
HTLV-I Tax Induces Cellular Proteins that Activate the κB Element in the IL-2 Receptor α Gene
Science
IF0

