Botnet Detection with Hybrid Analysis on Flow Based and Graph Based Features of Network Traffic

被引:10
|
作者
Shang, Yaoyao [1 ,2 ]
Yang, Shuangmao [2 ]
Wang, Wei [1 ,2 ]
机构
[1] Beijing Jiaotong Univ, Beijing Key Lab Secur & Privacy Intelligent Trans, 3 Shangyuancun, Beijing 100044, Peoples R China
[2] Sci & Technol Elect Informat Control Lab, Chengdu 610036, Sichuan, Peoples R China
来源
CLOUD COMPUTING AND SECURITY, PT II | 2018年 / 11064卷
关键词
Botnet detection; Network traffic; Network security; AUDIT DATA STREAMS; BEHAVIOR; APPS;
D O I
10.1007/978-3-030-00009-7_55
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Botnets have become one of the most serious threats to cyber infrastructure. Many existing botnet detection approaches become invalid due to botnet structure sophistication or encryption of payload of the traffic. In this work, we propose an effective anomaly-based botnet detection method by hybrid analysis of flow based and graph-based features of network traffic. Frist, from network traffic we extract 15 statistical aggregated flow based features as well as 7 types of graph based features, such as in degree, out degree, in degree weight, out degree weight, node betweenness centrality, local clustering coefficient and PageRank. Second, we employ K-means, k-NN and One-class SVM to detect bots based on the hybrid analysis of these two types of features. Finally, we collect a large size of network traffic in real computing environment by implementing 5 different botnets including newly propagated Mirai and others like Athena and Black energy. The extensive experimental results show that our method based on the hybrid analysis is better than the method of individual analysis in terms of detection accuracy. It achieves the best performance with 96.62% of F-score. The experimental results also demonstrate the effectiveness of our method on the detection of novel botnets like Mirai, Athena and Black energy.
引用
收藏
页码:612 / 621
页数:10
相关论文
共 50 条
  • [41] A Novel Traffic Analysis Model for Botnet Discovery in Dynamic Network
    Panimalar, P.
    Rameshkumar, K.
    ARABIAN JOURNAL FOR SCIENCE AND ENGINEERING, 2019, 44 (04) : 3033 - 3042
  • [42] OneR-DQN: a botnet traffic detection model based on deep Q network algorithm in deep reinforcement learning
    Hu Y.
    Zhao Y.
    Feng Y.
    Ma X.
    International Journal of Security and Networks, 2024, 19 (01) : 31 - 42
  • [43] DeDroid: A Mobile Botnet Detection Approach Based on Static Analysis
    Karim, Ahmad
    Salleh, Rosli
    Shah, Syed Adeel Ali
    IEEE 12TH INT CONF UBIQUITOUS INTELLIGENCE & COMP/IEEE 12TH INT CONF ADV & TRUSTED COMP/IEEE 15TH INT CONF SCALABLE COMP & COMMUN/IEEE INT CONF CLOUD & BIG DATA COMP/IEEE INT CONF INTERNET PEOPLE AND ASSOCIATED SYMPOSIA/WORKSHOPS, 2015, : 1327 - 1332
  • [44] Traffic Feature-Based Botnet Detection Scheme Emphasizing the Importance of Long Patterns
    An, Yichen
    Haruta, Shuichiro
    Choi, Sanghun
    Sasase, Iwao
    IMAGE PROCESSING AND COMMUNICATIONS: TECHNIQUES, ALGORITHMS AND APPLICATIONS, 2020, 1062 : 181 - 188
  • [45] Traffic feature-based botnet detection scheme emphasizing the importance of long patterns
    An, Yichen
    Haruta, Shuichiro
    Choi, Sanghun
    Sasase, Iwao
    IEICE COMMUNICATIONS EXPRESS, 2020, 9 (01): : 7 - 12
  • [46] Android Malware Detection and Categorization Based on Conversation-level Network Traffic Features
    Abuthawabeh, Mohammad Kamel A.
    Mahmoud, Khaled W.
    2019 INTERNATIONAL ARAB CONFERENCE ON INFORMATION TECHNOLOGY (ACIT), 2019, : 42 - 47
  • [47] Efficient DDoS flood attack detection using dynamic thresholding on flow-based network traffic
    David, Jisa
    Thomas, Ciza
    COMPUTERS & SECURITY, 2019, 82 : 284 - 295
  • [48] Anomaly Detection Based on Spatio-Temporal and Sparse Features of Network Traffic in VANETs
    Nie, Laisen
    Wu, Yixuan
    Wang, Huizhi
    Li, Yongkang
    IEEE ACCESS, 2019, 7 : 177954 - 177964
  • [49] Network Traffic Classification based on Single Flow Time Series Analysis
    Koumar, Josef
    Hynek, Karel
    Cejka, Tomas
    2023 19TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT, CNSM, 2023,
  • [50] A Novel Botnet Detection Method Based on Preprocessing Data Packet by Graph Structure Clustering
    Kong, Xinling
    Chen, Yonghong
    Tian, Hui
    Wang, Tian
    Cai, Yiqiao
    Chen, Xin
    2016 INTERNATIONAL CONFERENCE ON CYBER-ENABLED DISTRIBUTED COMPUTING AND KNOWLEDGE DISCOVERY PROCEEDINGS - CYBERC 2016, 2016, : 42 - 45