arrow
返回

Ensemble Network Graph-Based Classification for Botnet Detection Using Adaptive Weighting and Feature Extraction

delete2025-01-01
delete0
delete
OA
AI
M
Muhammad Aidiel Rachman Putra
T
Tohari Ahmad *
D
Dandy Pramana Hostiadi
R
Royyana Muslim Ijtihadie
DOI:10.1109/ACCESS.2025.3541125delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
The number of cybersecurity threats increases every year due to the rapid improvement of methods and tools used by hackers to infect devices. These threats form a network, which is called a botnet, to send and receive commands. Botnets can launch malicious attacks using malware to infect targets in the network and then control them to do illegal things. Previous research has demonstrated that security systems can identify attacks by analyzing communication among bots in a network using a graphing approach. While this analytical method demonstrates satisfactory accuracy, it still faces challenges related to low recall, precision, and F1-score, due to issues such as imbalanced data and the complexity of botnet behavior. This research addresses these challenges by analyzing network flow using adaptive weighting and feature extraction. Network flows are represented in a graph with IP addresses as vertices and communication links between IP addresses as edges. Since botnet attack activity forms a relatively small percentage compared with millions of recorded network flow data, the data is grouped using time gap analysis to handle the imbalance problem. Furthermore, network flows are represented in two graphs, and each edge is weighted based on the 16 types of weighting. The graph representation and weighting output are stored in out-degree and in-degree graph metadata for classification. The analysis is carried out in an ensemble manner with weighting and threshold values to determine whether an IP address is a botnet or a normal host. The experimental results obtained using CTU-13, NCC, and NCC-2 datasets produce reliable performance with an average accuracy of 99.99%, along with 80.91% precision, 93.10% recall, 82.15% f1-score and 39.55 second execution time. The proposed model can function as an effective tool for the forensic analysis of botnet attacks, allowing network administrators to analyze the characteristics of botnet activities and anticipate potential future threats.
Keyword:
Botnet detection
graph-based representation
machine learning
network security
information security
network infrastructure
Botnet detection
graph-based representation
machine learning
network security
information security
network infrastructure

期刊

IEEE Access 封面图
IEEE Access
IF:
3.6
论文数:
9.8W
被引数:
29.4W

机构

I
institut teknologi sepuluh nopember
学者数:
2.1K
论文数: 1.2K
被引数: 0
引用论文

引用论文

Heterocyclic chelating agents. Part I. Metal complexes of 4-2′-pyridylimidazole
err1967-01-01
err0
PREAI
errW. J. Eilbeck; F. Holmes; G. G. Phillips; A. E. Underhill
err分享
err收藏
The evolution of Mirai botnet scans over a six-year period
err2023-12-01
err15
errOAAI
errAffinito, Antonia; Zinno, Stefania; Stanco, Giovanni; Botta, Alessio; Ventre, Giorgio
err分享
err收藏
err分享
err收藏
Botnet Detection Approach Using Graph-Based Machine Learning
err2021-01-01
err33
errOAAI
errAlharbi, Afnan; Alsubhi, Khalid
err分享
err收藏
Evolving Malware and DDoS Attacks: Decadal Longitudinal Study
err2024-01-01
err11
errOAAI
errFalowo, Olufunsho I.; Ozer, Murat; Li, Chengcheng; Abdo, Jacques Bou
err分享
err收藏
An empirical comparison of botnet detection methods
err2014-09-01
err516
errOAAI
errGarcia, S.; Grill, M.; Stiborek, J.; Zunino, A.
err分享
err收藏
On Detecting and Classifying DGA Botnets and their Families
err2022-02-01
err26
errOAAI
errTong Anh Tuan; Long, Hoang Viet; Taniar, David
err分享
err收藏
err分享
err收藏
学者 查看更多内容