Automatic Botnet Attack Identification Based on Machine Learning

被引:3
|
作者
Li P.H. [1 ]
Xu J. [1 ]
Xu Z.Y. [1 ]
Chen S. [1 ]
Niu B.W. [2 ]
Yin J. [1 ]
Sun X.F. [1 ]
Lan H.L. [1 ]
Chen L.L. [3 ]
机构
[1] Jiangsu Police Institute, Nanjing
[2] Public Security Department of Jiangsu Province, Nanjing
[3] The University of Adelaide, Adelaide, 5005, SA
来源
Computers, Materials and Continua | 2022年 / 73卷 / 02期
关键词
Honeypot; log; machine learning; network attack;
D O I
10.32604/cmc.2022.029969
中图分类号
学科分类号
摘要
At present, the severe network security situation has put forward high requirements for network security defense technology. In order to automate botnet threat warning, this paper researches the types and characteristics of Botnet. Botnet has special characteristics in attributes such as packets, attack time interval, and packet size. In this paper, the attack data is annotated by means of string recognition and expert screening. The attack features are extracted from the labeled attack data, and then use K-means for cluster analysis. The clustering results show that the same attack data has its unique characteristics, and the automatic identification of network attacks is realized based on these characteristics. At the same time, based on the collection and attribute extraction of Botnet attack data, this paper uses RF, GBM, XGBOOST and other machine learning models to test the warning results, and automatically analyzes the attack by importing attack data. In the early warning analysis results, the accuracy rates of different models are obtained. Through the descriptive values of the three accuracy rates of Accuracy, Precision, and F1_Score, the early warning effect of each model can be comprehensively displayed. Among the five algorithms used in this paper, three have an accuracy rate of over 90%. The three models with the highest accuracy are used in the early warning model. The research shows that cyberattacks can be accurately predicted. When this technology is applied to the protection system, accurate early warning can be given before a network attack is launched. © 2022 Tech Science Press. All rights reserved.
引用
收藏
页码:3847 / 3860
页数:13
相关论文
共 50 条
  • [1] Machine learning based Botnet Identification Traffic
    Azab, Ahmad
    Alazab, Mamoun
    Aiash, Mahdi
    2016 IEEE TRUSTCOM/BIGDATASE/ISPA, 2016, : 1788 - 1794
  • [2] Botnet Attack Identification Based on SDN
    Dimiter, Avresky
    Dobrev, Dobrin
    CYBER SECURITY, CRYPTOLOGY, AND MACHINE LEARNING, 2022, 13301 : 162 - 169
  • [3] Botnet Attack Detection in IoT Using Machine Learning
    Alissa, Khalid
    Alyas, Tahir
    Zafar, Kashif
    Abbas, Qaiser
    Tabassum, Nadia
    Sakib, Shadman
    COMPUTATIONAL INTELLIGENCE AND NEUROSCIENCE, 2022, 2022
  • [4] Machine Learning-Based IoT-Botnet Attack Detection with Sequential Architecture†
    Soe, Yan Naung
    Feng, Yaokai
    Santosa, Paulus Insap
    Hartanto, Rudy
    Sakurai, Kouichi
    SENSORS, 2020, 20 (16) : 1 - 15
  • [5] Performance evaluation of Botnet DDoS attack detection using machine learning
    Tuan, Tong Anh
    Long, Hoang Viet
    Son, Le Hoang
    Kumar, Raghvendra
    Priyadarshini, Ishaani
    Son, Nguyen Thi Kim
    EVOLUTIONARY INTELLIGENCE, 2020, 13 (02) : 283 - 294
  • [6] Performance evaluation of Botnet DDoS attack detection using machine learning
    Tong Anh Tuan
    Hoang Viet Long
    Le Hoang Son
    Raghvendra Kumar
    Ishaani Priyadarshini
    Nguyen Thi Kim Son
    Evolutionary Intelligence, 2020, 13 : 283 - 294
  • [7] Overview of Botnet Detection Based on Machine Learning
    Dong Xiaxin
    Hu Jianwei
    Cui Yanpeng
    2018 3RD INTERNATIONAL CONFERENCE ON MECHANICAL, CONTROL AND COMPUTER ENGINEERING (ICMCCE), 2018, : 476 - 479
  • [8] Automatic Identification Fingerprint Based on Machine Learning Method
    Long The Nguyen
    Huong Thu Nguyen
    Alexander Diomidovich Afanasiev
    Tao Van Nguyen
    Journal of the Operations Research Society of China, 2022, 10 : 849 - 860
  • [9] Automatic Identification Fingerprint Based on Machine Learning Method
    Nguyen, Long The
    Nguyen, Huong Thu
    Afanasiev, Alexander Diomidovich
    Nguyen, Tao Van
    JOURNAL OF THE OPERATIONS RESEARCH SOCIETY OF CHINA, 2022, 10 (04) : 849 - 860
  • [10] Hybrid Machine Learning Model for Efficient Botnet Attack Detection in IoT Environment
    Ali, Mudasir
    Shahroz, Mobeen
    Mushtaq, Muhammad Faheem
    Alfarhood, Sultan
    Safran, Mejdl
    Ashraf, Imran
    IEEE ACCESS, 2024, 12 : 40682 - 40699