arrow
返回

Benchmark-Based Reference Model for Evaluating Botnet Detection Tools Driven by Traffic-Flow Analytics

delete2020-08-12
delete28
delete
OA
AI
K
Katherinne Shirley Huancayo Ramos
M
Marco Antonio Sotelo Monge *
J
Jorge Maestre Vidal
DOI:10.3390/s20164501delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
Botnets are some of the most recurrent cyber-threats, which take advantage of the wide heterogeneity of endpoint devices at the Edge of the emerging communication environments for enabling the malicious enforcement of fraud and other adversarial tactics, including malware, data leaks or denial of service. There have been significant research advances in the development of accurate botnet detection methods underpinned on supervised analysis but assessing the accuracy and performance of such detection methods requires a clear evaluation model in the pursuit of enforcing proper defensive strategies. In order to contribute to the mitigation of botnets, this paper introduces a novel evaluation scheme grounded on supervised machine learning algorithms that enable the detection and discrimination of different botnets families on real operational environments. The proposal relies on observing, understanding and inferring the behavior of each botnet family based on network indicators measured at flow-level. The assumed evaluation methodology contemplates six phases that allow building a detection model against botnet-related malware distributed through the network, for which five supervised classifiers were instantiated were instantiated for further comparisons-Decision Tree, Random Forest, Naive Bayes Gaussian, Support Vector Machine and K-Neighbors. The experimental validation was performed on two public datasets of real botnet traffic-CIC-AWS-2018 and ISOT HTTP Botnet. Bearing the heterogeneity of the datasets, optimizing the analysis with the Grid Search algorithm led to improve the classification results of the instantiated algorithms. An exhaustive evaluation was carried out demonstrating the adequateness of our proposal which prompted that Random Forest and Decision Tree models are the most suitable for detecting different botnet specimens among the chosen algorithms. They exhibited higher precision rates whilst analyzing a large number of samples with less processing time. The variety of testing scenarios were deeply assessed and reported to set baseline results for future benchmark analysis targeted on flow-based behavioral patterns.
Keyword:
botnet
deep learning
graph mining
malware detection
machine learning
traffic-flow
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

Sensors 封面图
Sensors
IF:
3.5
论文数:
7.2W
被引数:
20.9W

机构

Universidad de Lima 封面图
Universidad de Lima
学者数:
270
论文数: 195
被引数: 174
I
indra
学者数:
59
论文数: 46
被引数: 0
引用论文

引用论文

err分享
err收藏
Machine Learning-Based Malicious Application Detection of Android基于机器学习的Android恶意应用检测
err2017-01-01
err49
errOAAI
errWei, Linfeng; Luo, Weiqi; Weng, Jian; Zhong, Yanjun; zhang, Xiaoqian; Yan, Zheng
err分享
err收藏
The Small Warship
err1946-06-01
err0
PREAI
errGeorge C. Homans
err分享
err收藏
err分享
err收藏
Integrative Analysis Reveals Relationships of Genetic and Epigenetic Alterations in Osteosarcoma
err2012-11-07
err0
errOAAI
errStine H. Kresse; Halfdan Rydbeck; Magne Skårn; Heidi M. Namløs; Ana H. Barragan-Polania; Anne-Marie Cleton-Jansen; Massimo Serra; Knut Liestøl; Pancras C. W. Hogendoorn; Eivind Hovig; Ola Myklebost; Leonardo A. Meza-Zepeda
err分享
err收藏
Traffic-flow analysis for source-side DDoS recognition on 5G environments
err2019-06-01
err31
PREAI
errSotelo Monge, Marco Antonio; Herranz Gonzalez, Andres; Lorenzo Fernandez, Borja; Maestre Vidal, Diego; Rius Garcia, Guillermo; Maestre Vidal, Jorge
err分享
err收藏
A novel statistical analysis and autoencoder driven intelligent intrusion detection approach
err2020-04-01
err148
PREAI
errIeracitano, Cosimo; Adeel, Ahsan; Morabito, Francesco Carlo; Hussain, Amir
err分享
err收藏
学者 查看更多内容