A novel Machine Learning-based approach for the detection of SSH botnet infection

被引:15
|
作者
Martinez Garre, Jose Tomas [1 ]
Gil Perez, Manuel [1 ]
Ruiz-Martinez, Antonio [1 ]
机构
[1] Univ Murcia, Dept Informat & Commun Engn, Murcia 30100, Spain
基金
欧盟地平线“2020”;
关键词
Botnet; Machine learning; Zero-day malware; Honeypot; High interaction;
D O I
10.1016/j.future.2020.09.004
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Botnets are causing severe damages to users, companies, and governments through information theft, abuse of online services, DDoS attacks, etc. Although significant research is being made to detect them and mitigate their effect, they are exponentially increasing due to new zero-day attacks, a variation of their behavior, and obfuscation techniques. High Interaction Honeypots (HIH) are the only honeypots able to capture attacks and log all the information generated by attackers when setting up a botnet. The data generated is being processed using Machine Learning (ML) techniques for detection since they can detect hidden patterns. However, so far, research has been focused on intermediate phases of the botnet's life cycle during operation, underestimating the initial phase of infection. To the best of our knowledge, this is the first solution in the infection phase of SSH-based botnets. Therefore, we have designed an approach based on an SSH-based HIH to generate a dataset consisting of executed commands and network information. Herein, we have applied ML techniques for the development of a real-time detection model. This approach reached a very high level of prediction and zero false negatives. Indeed, our system detected all known and unknown SSH sessions intended to infect our honeypots. Thus, our research has demonstrated that new SSH infections can be detected through ML techniques. (C) 2020 Elsevier B.V. All rights reserved.
引用
收藏
页码:387 / 396
页数:10
相关论文
共 50 条
  • [41] Android botnet detection using machine learning
    Rasheed M.M.
    Faieq A.K.
    Hashim A.A.
    Rasheed, Mohammad M. (mohammad.rasheed@uoitc.edu.iq), 1600, International Information and Engineering Technology Association (25): : 127 - 130
  • [42] Study on Machine Learning Techniques for Botnet Detection
    Silva, L.
    Utimura, L.
    Costa, K.
    Silva, M.
    Prado, S.
    IEEE LATIN AMERICA TRANSACTIONS, 2020, 18 (05) : 881 - 888
  • [43] Botnet Detection via Machine Learning Techniques
    Wang, Haofan
    2022 INTERNATIONAL CONFERENCE ON BIG DATA, INFORMATION AND COMPUTER NETWORK (BDICN 2022), 2022, : 836 - 841
  • [44] An efficient botnet detection approach based on feature learning and classification
    Padmavathi, B.
    Muthukumar, B.
    JOURNAL OF CONTROL AND DECISION, 2023, 10 (01) : 40 - 53
  • [45] Explaining Machine Learning Predictions in Botnet Detection
    Miller, Sean
    Busby-Earle, Curtis
    ARTIFICIAL INTELLIGENCE AND SOFT COMPUTING, ICAISC 2022, PT I, 2023, 13588 : 298 - 309
  • [46] Multiclass Machine Learning Based Botnet Detection in Software Defined Networks
    Tariq, Farhan
    Baig, Shamim
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2019, 19 (03): : 150 - 156
  • [47] An Ensemble Machine Learning Botnet Detection Framework Based on Noise Filtering
    Liu, Tzong-Jye
    Lin, Tze-Shiun
    Chen, Ching-Wen
    JOURNAL OF INTERNET TECHNOLOGY, 2021, 22 (06): : 1347 - 1357
  • [48] Hybrid rule-based botnet detection approach using machine learning for analysing DNS traffic
    Al-Mashhadi, Saif
    Anbar, Mohammed
    Hasbullah, Iznan
    Alamiedy, Taief Alaa
    PEERJ COMPUTER SCIENCE, 2021, 7 : 1 - 34
  • [49] A novel graph-based approach for IoT botnet detection
    Huy-Trung Nguyen
    Quoc-Dung Ngo
    Van-Hoang Le
    International Journal of Information Security, 2020, 19 : 567 - 577
  • [50] A novel graph-based approach for IoT botnet detection
    Huy-Trung Nguyen
    Quoc-Dung Ngo
    Van-Hoang Le
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2020, 19 (05) : 567 - 577