Multiclass Machine Learning Based Botnet Detection in Software Defined Networks

被引:0
|
作者
Tariq, Farhan [1 ]
Baig, Shamim [2 ]
机构
[1] Ctr Adv Studies Engn, Elect & Comp Engn, Islamabad, Pakistan
[2] HITEC Univ, Comp Sci & Engn, Taxila, Pakistan
来源
INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY | 2019年 / 19卷 / 03期
关键词
botnet detection; malware; Multiclass machine learning; NBA; SDN; TSDR; OpenFlow; Opendaylight; flows;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Continuously evolving nature of botnet by using innovative approaches and technologies derives the need for continuous improvement of botnet detection solutions. The state of the art network approaches in literature targeting network header level information only for behavioral-based detection. These techniques applying machine learning algorithms to automatically detect botnet patterns from network flows. The current work in flow-based approaches exploring SDNs to overcome traditional IP network complexities. The Software defined network technology platform with centralized visibility and control provide an opportunity to redesign these approaches. The current SDNs based proposed approaches apply binary classification to decide if the detected flow belongs to a botnet or not. This work proposed a multiclass machine learning based approach to address botnet problem in SDNs. The proposed scheme applies multiple binary classifiers each trained for a specific type of botnet class. These focused classifiers performed better in the detection of the specific type of botnet. The proposed approach uses the flow trace concept. The features are extracted for each detected flow trace and fed into these focused classifiers. These features are examined by all classifiers and detected label is added for each processed flow trace. These labels are aggregated in the second stage to decide if a flow trace belongs to any botnet class or not. This additional information of a class of the detected botnet trace is helpful during the incident response process. The experiments for evaluation of the proposed work are performed on real-world traffic traces and the result shows promising detection rate with the capability to detect unknown botnet.
引用
收藏
页码:150 / 156
页数:7
相关论文
共 50 条
  • [1] Machine Learning-Based Botnet Detection in Software-Defined Network: A Systematic Review
    Shinan, Khlood
    Alsubhi, Khalid
    Alzahrani, Ahmed
    Ashraf, Muhammad Usman
    SYMMETRY-BASEL, 2021, 13 (05):
  • [2] Machine Learning Based Intrusion Detection System for Software Defined Networks
    Abubakar, Atiku
    Pranggono, Bernardi
    2017 SEVENTH INTERNATIONAL CONFERENCE ON EMERGING SECURITY TECHNOLOGIES (EST), 2017, : 138 - 143
  • [3] A Survey of Low Rate DDoS Detection Techniques Based on Machine Learning in Software-Defined Networks
    Alashhab, Abdussalam Ahmed
    Zahid, Mohd Soperi Mohd
    Azim, Mohamed A.
    Daha, Muhammad Yunis
    Isyaku, Babangida
    Ali, Shimhaz
    SYMMETRY-BASEL, 2022, 14 (08):
  • [4] Overview of Botnet Detection Based on Machine Learning
    Dong Xiaxin
    Hu Jianwei
    Cui Yanpeng
    2018 3RD INTERNATIONAL CONFERENCE ON MECHANICAL, CONTROL AND COMPUTER ENGINEERING (ICMCCE), 2018, : 476 - 479
  • [5] Botnet Detection using Software Defined Networking
    Wijesinghe, Udaya
    Tupakula, Udaya
    Varadharajan, Vijay
    2015 22ND INTERNATIONAL CONFERENCE ON TELECOMMUNICATIONS (ICT), 2015, : 219 - 224
  • [6] BotGuard:Lightweight Real-Time Botnet Detection in Software Defined Networks
    CHEN Jing
    CHENG Xi
    DU Ruiying
    HU Li
    WANG Chiheng
    Wuhan University Journal of Natural Sciences, 2017, 22 (02) : 103 - 113
  • [7] Botnet Detection Approach Using Graph-Based Machine Learning
    Alharbi, Afnan
    Alsubhi, Khalid
    IEEE ACCESS, 2021, 9 (09): : 99166 - 99180
  • [8] Machine-Learning-Based Traffic Classification in Software-Defined Networks
    Serag, Rehab H.
    Abdalzaher, Mohamed S.
    Elsayed, Hussein Abd El Atty
    Sobh, M.
    Krichen, Moez
    Salim, Mahmoud M.
    ELECTRONICS, 2024, 13 (06)
  • [9] Intrusion detection systems for software-defined networks: a comprehensive study on machine learning-based techniques
    Mustafa, Zaid
    Amin, Rashid
    Aldabbas, Hamza
    Ahmed, Naeem
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2024, 27 (07): : 9635 - 9661
  • [10] The Role of Machine Learning in Botnet Detection
    Miller, Sean
    Busby-Earle, Curtis
    2016 11TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2016, : 359 - 364