Automatic Botnet Attack Identification Based on Machine Learning

被引:3
|
作者
Li P.H. [1 ]
Xu J. [1 ]
Xu Z.Y. [1 ]
Chen S. [1 ]
Niu B.W. [2 ]
Yin J. [1 ]
Sun X.F. [1 ]
Lan H.L. [1 ]
Chen L.L. [3 ]
机构
[1] Jiangsu Police Institute, Nanjing
[2] Public Security Department of Jiangsu Province, Nanjing
[3] The University of Adelaide, Adelaide, 5005, SA
关键词
Honeypot; log; machine learning; network attack;
D O I
10.32604/cmc.2022.029969
中图分类号
学科分类号
摘要
At present, the severe network security situation has put forward high requirements for network security defense technology. In order to automate botnet threat warning, this paper researches the types and characteristics of Botnet. Botnet has special characteristics in attributes such as packets, attack time interval, and packet size. In this paper, the attack data is annotated by means of string recognition and expert screening. The attack features are extracted from the labeled attack data, and then use K-means for cluster analysis. The clustering results show that the same attack data has its unique characteristics, and the automatic identification of network attacks is realized based on these characteristics. At the same time, based on the collection and attribute extraction of Botnet attack data, this paper uses RF, GBM, XGBOOST and other machine learning models to test the warning results, and automatically analyzes the attack by importing attack data. In the early warning analysis results, the accuracy rates of different models are obtained. Through the descriptive values of the three accuracy rates of Accuracy, Precision, and F1_Score, the early warning effect of each model can be comprehensively displayed. Among the five algorithms used in this paper, three have an accuracy rate of over 90%. The three models with the highest accuracy are used in the early warning model. The research shows that cyberattacks can be accurately predicted. When this technology is applied to the protection system, accurate early warning can be given before a network attack is launched. © 2022 Tech Science Press. All rights reserved.
引用
收藏
页码:3847 / 3860
页数:13
相关论文
共 50 条
  • [41] Hybrid Feature Selection Models for Machine Learning Based Botnet Detection in IoT Networks
    Guerra-Manzanares, Alejandro
    Nomm, Sven
    Bahsi, Hayretdin
    2019 INTERNATIONAL CONFERENCE ON CYBERWORLDS (CW), 2019, : 324 - 327
  • [42] Botnet Vulnerability Intelligence Clustering Classification Mining and Countermeasure Algorithm Based on Machine Learning
    Chu, Zenan
    Han, Yi
    Zhao, Kai
    IEEE ACCESS, 2019, 7 : 182309 - 182319
  • [43] Reviewing various feature selection techniques in machine learning-based botnet detection
    Baruah, Sangita
    Borah, Dhruba Jyoti
    Deka, Vaskar
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2024, 36 (12)
  • [44] A Machine Learning Based Method for Automatic Identification of Disaster Related Information Using Twitter Data
    Christidou, Athina Ntiana
    Drakaki, Maria
    Linardos, Vasileios
    INTELLIGENT AND FUZZY SYSTEMS: DIGITAL ACCELERATION AND THE NEW NORMAL, INFUS 2022, VOL 2, 2022, 505 : 70 - 76
  • [45] Detection of IoT Botnet Cyber Attacks Using Machine Learning
    Khaleefah A.D.
    Al-Mashhadi H.M.
    Informatica (Slovenia), 2023, 47 (06): : 55 - 64
  • [46] Machine Learning Algorithms on Botnet Traffic: Ensemble and Simple Algorithms
    McKay, Rob
    Pendleton, Brian
    Britt, James
    Nakhavanit, Ben
    PROCEEDINGS OF THE 2019 THE 3RD INTERNATIONAL CONFERENCE ON COMPUTE AND DATA ANALYSIS (ICCDA 2019), 2019, : 31 - 35
  • [47] Machine Learning Based Primary User Emulation Attack Detection
    Camana, Mario R.
    Garcia, Carla E.
    Koo, Insoo
    Shakhov, Vladimir
    2022 IEEE INTERNATIONAL BLACK SEA CONFERENCE ON COMMUNICATIONS AND NETWORKING (BLACKSEACOM), 2022, : 244 - 248
  • [48] Backdoor Attack on Machine Learning Based Android Malware Detectors
    Li, Chaoran
    Chen, Xiao
    Wang, Derui
    Wen, Sheng
    Ahmed, Muhammad Ejaz
    Camtepe, Seyit
    Xiang, Yang
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2022, 19 (05) : 3357 - 3370
  • [49] Cooperative defense of DDoS attack based on machine learning in SDN
    Shang L.
    Chen M.
    Zhang L.
    Liu X.
    Shi T.
    Li B.
    Dianli Xitong Baohu yu Kongzhi/Power System Protection and Control, 2021, 49 (16): : 170 - 176
  • [50] Machine Learning-Based Attack Detection for the Internet of Things
    Bikila, Dawit Dejene
    Capek, Jan
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2025, 166