Automatic Botnet Attack Identification Based on Machine Learning

被引:3
|
作者
Li P.H. [1 ]
Xu J. [1 ]
Xu Z.Y. [1 ]
Chen S. [1 ]
Niu B.W. [2 ]
Yin J. [1 ]
Sun X.F. [1 ]
Lan H.L. [1 ]
Chen L.L. [3 ]
机构
[1] Jiangsu Police Institute, Nanjing
[2] Public Security Department of Jiangsu Province, Nanjing
[3] The University of Adelaide, Adelaide, 5005, SA
关键词
Honeypot; log; machine learning; network attack;
D O I
10.32604/cmc.2022.029969
中图分类号
学科分类号
摘要
At present, the severe network security situation has put forward high requirements for network security defense technology. In order to automate botnet threat warning, this paper researches the types and characteristics of Botnet. Botnet has special characteristics in attributes such as packets, attack time interval, and packet size. In this paper, the attack data is annotated by means of string recognition and expert screening. The attack features are extracted from the labeled attack data, and then use K-means for cluster analysis. The clustering results show that the same attack data has its unique characteristics, and the automatic identification of network attacks is realized based on these characteristics. At the same time, based on the collection and attribute extraction of Botnet attack data, this paper uses RF, GBM, XGBOOST and other machine learning models to test the warning results, and automatically analyzes the attack by importing attack data. In the early warning analysis results, the accuracy rates of different models are obtained. Through the descriptive values of the three accuracy rates of Accuracy, Precision, and F1_Score, the early warning effect of each model can be comprehensively displayed. Among the five algorithms used in this paper, three have an accuracy rate of over 90%. The three models with the highest accuracy are used in the early warning model. The research shows that cyberattacks can be accurately predicted. When this technology is applied to the protection system, accurate early warning can be given before a network attack is launched. © 2022 Tech Science Press. All rights reserved.
引用
收藏
页码:3847 / 3860
页数:13
相关论文
共 50 条
  • [1] Machine Learning-Based IoT-Botnet Attack Detection with Sequential Architecture†
    Soe, Yan Naung
    Feng, Yaokai
    Santosa, Paulus Insap
    Hartanto, Rudy
    Sakurai, Kouichi
    SENSORS, 2020, 20 (16) : 1 - 15
  • [2] Performance evaluation of Botnet DDoS attack detection using machine learning
    Tuan, Tong Anh
    Long, Hoang Viet
    Son, Le Hoang
    Kumar, Raghvendra
    Priyadarshini, Ishaani
    Son, Nguyen Thi Kim
    EVOLUTIONARY INTELLIGENCE, 2020, 13 (02) : 283 - 294
  • [3] Performance evaluation of Botnet DDoS attack detection using machine learning
    Tong Anh Tuan
    Hoang Viet Long
    Le Hoang Son
    Raghvendra Kumar
    Ishaani Priyadarshini
    Nguyen Thi Kim Son
    Evolutionary Intelligence, 2020, 13 : 283 - 294
  • [4] Overview of Botnet Detection Based on Machine Learning
    Dong Xiaxin
    Hu Jianwei
    Cui Yanpeng
    2018 3RD INTERNATIONAL CONFERENCE ON MECHANICAL, CONTROL AND COMPUTER ENGINEERING (ICMCCE), 2018, : 476 - 479
  • [5] Automatic Identification Fingerprint Based on Machine Learning Method
    Nguyen, Long The
    Nguyen, Huong Thu
    Afanasiev, Alexander Diomidovich
    Nguyen, Tao Van
    JOURNAL OF THE OPERATIONS RESEARCH SOCIETY OF CHINA, 2022, 10 (04) : 849 - 860
  • [6] Automatic Identification Fingerprint Based on Machine Learning Method
    Long The Nguyen
    Huong Thu Nguyen
    Alexander Diomidovich Afanasiev
    Tao Van Nguyen
    Journal of the Operations Research Society of China, 2022, 10 : 849 - 860
  • [7] An Aggregated Mutual Information Based Feature Selection with Machine Learning Methods for Enhancing IoT Botnet Attack Detection
    Al-Sarem, Mohammed
    Saeed, Faisal
    Alkhammash, Eman H.
    Alghamdi, Norah Saleh
    SENSORS, 2022, 22 (01)
  • [8] Review of Botnet Attack Detection in SDN-Enabled IoT Using Machine Learning
    Negera, Worku Gachena
    Schwenker, Friedhelm
    Debelee, Taye Girma
    Melaku, Henock Mulugeta
    Ayano, Yehualashet Megeresa
    SENSORS, 2022, 22 (24)
  • [9] A novel Machine Learning-based approach for the detection of SSH botnet infection
    Martinez Garre, Jose Tomas
    Gil Perez, Manuel
    Ruiz-Martinez, Antonio
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2021, 115 : 387 - 396
  • [10] A Machine Learning Based Automatic Hardware Trojan Attack Space Exploration and Benchmarking Framework
    Cruz, Jonathan
    Gaikwad, Pravin
    Nair, Abhishek
    Chakraborty, Prabuddha
    Bhunia, Swarup
    2022 ASIAN HARDWARE ORIENTED SECURITY AND TRUST SYMPOSIUM (ASIANHOST), 2022,