Multiclass Machine Learning Based Botnet Detection in Software Defined Networks

被引:0
|
作者
Tariq, Farhan [1 ]
Baig, Shamim [2 ]
机构
[1] Ctr Adv Studies Engn, Elect & Comp Engn, Islamabad, Pakistan
[2] HITEC Univ, Comp Sci & Engn, Taxila, Pakistan
关键词
botnet detection; malware; Multiclass machine learning; NBA; SDN; TSDR; OpenFlow; Opendaylight; flows;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Continuously evolving nature of botnet by using innovative approaches and technologies derives the need for continuous improvement of botnet detection solutions. The state of the art network approaches in literature targeting network header level information only for behavioral-based detection. These techniques applying machine learning algorithms to automatically detect botnet patterns from network flows. The current work in flow-based approaches exploring SDNs to overcome traditional IP network complexities. The Software defined network technology platform with centralized visibility and control provide an opportunity to redesign these approaches. The current SDNs based proposed approaches apply binary classification to decide if the detected flow belongs to a botnet or not. This work proposed a multiclass machine learning based approach to address botnet problem in SDNs. The proposed scheme applies multiple binary classifiers each trained for a specific type of botnet class. These focused classifiers performed better in the detection of the specific type of botnet. The proposed approach uses the flow trace concept. The features are extracted for each detected flow trace and fed into these focused classifiers. These features are examined by all classifiers and detected label is added for each processed flow trace. These labels are aggregated in the second stage to decide if a flow trace belongs to any botnet class or not. This additional information of a class of the detected botnet trace is helpful during the incident response process. The experiments for evaluation of the proposed work are performed on real-world traffic traces and the result shows promising detection rate with the capability to detect unknown botnet.
引用
收藏
页码:150 / 156
页数:7
相关论文
共 50 条
  • [1] Machine Learning-Based Botnet Detection in Software-Defined Network: A Systematic Review
    Shinan, Khlood
    Alsubhi, Khalid
    Alzahrani, Ahmed
    Ashraf, Muhammad Usman
    SYMMETRY-BASEL, 2021, 13 (05):
  • [2] Machine Learning Based Intrusion Detection System for Software Defined Networks
    Abubakar, Atiku
    Pranggono, Bernardi
    2017 SEVENTH INTERNATIONAL CONFERENCE ON EMERGING SECURITY TECHNOLOGIES (EST), 2017, : 138 - 143
  • [3] An entropy and machine learning based approach for DDoS attacks detection in software defined networks
    Hassan, Amany I.
    Abd El Reheem, Eman
    Guirguis, Shawkat K.
    SCIENTIFIC REPORTS, 2024, 14 (01):
  • [4] Designing a Network Intrusion Detection System Based on Machine Learning for Software Defined Networks
    Alzahrani, Abdulsalam O.
    Alenazi, Mohammed J. E.
    FUTURE INTERNET, 2021, 13 (05)
  • [5] Anomalous Rule Detection using Machine Learning in Software Defined Networks
    Sridharan, Vignesh
    Gurusamy, Mohan
    Leon-Garcia, Alberto
    2019 IEEE CONFERENCE ON NETWORK FUNCTION VIRTUALIZATION AND SOFTWARE DEFINED NETWORKS (IEEE NFV-SDN), 2019,
  • [6] Overview of Botnet Detection Based on Machine Learning
    Dong Xiaxin
    Hu Jianwei
    Cui Yanpeng
    2018 3RD INTERNATIONAL CONFERENCE ON MECHANICAL, CONTROL AND COMPUTER ENGINEERING (ICMCCE), 2018, : 476 - 479
  • [7] A DDoS Detection Method Based on Feature Engineering and Machine Learning in Software-Defined Networks
    Liu, Zhenpeng
    Wang, Yihang
    Feng, Fan
    Liu, Yifan
    Li, Zelin
    Shan, Yawei
    SENSORS, 2023, 23 (13)
  • [8] DGA-Based Botnet Detection Toward Imbalanced Multiclass Learning
    Chen, Yijing
    Pang, Bo
    Shao, Guolin
    Wen, Guozhu
    Chen, Xingshu
    TSINGHUA SCIENCE AND TECHNOLOGY, 2021, 26 (04) : 387 - 402
  • [9] DGA-Based Botnet Detection Toward Imbalanced Multiclass Learning
    Yijing Chen
    Bo Pang
    Guolin Shao
    Guozhu Wen
    Xingshu Chen
    TsinghuaScienceandTechnology, 2021, 26 (04) : 387 - 402
  • [10] Botnet Detection using Software Defined Networking
    Wijesinghe, Udaya
    Tupakula, Udaya
    Varadharajan, Vijay
    2015 22ND INTERNATIONAL CONFERENCE ON TELECOMMUNICATIONS (ICT), 2015, : 219 - 224