Feature Selection for Effective Botnet Detection Based on Periodicity of Traffic

被引:1
|
作者
Harsha, T. [1 ]
Asha, S. [1 ]
Soniya, B. [1 ]
机构
[1] SCT Coll Engn, Dept Comp Sci & Engn, Trivandrum, Kerala, India
来源
INFORMATION SYSTEMS SECURITY | 2016年 / 10063卷
关键词
Botnet; C&C server; Periodicity; Bot; HTTP;
D O I
10.1007/978-3-319-49806-5_26
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Botnets are networks that are composed with a set of compromised machines called bots that are remotely controlled by a botmaster. They pose a threatening remark to network communications and applications. A botnet relies on its command and control communication channel for performing attacks. C2 traffic occurs prior to any attack; hence, the detection of botnet's traffic helps in detecting the bots before any real attack happens. Recently, the HTTP based Botnet threat has become a serious challenge for security experts as Bots can be distributed quickly and stealthily. The HTTP Bots periodically connect to particular web pages or URLs to get commands and updates from the Botmaster. In fact, this identifiable periodic connection pattern has been used to detect HTTP Botnets. This paper proposes an idea for identifying bots that exhibit non periodic nature as well normal traffic that exhibit periodic nature. The proposed method reduces the false positive rate as well as increases the detection rate. For that a set of traffic features are taken from many detection methods and feature selection is made on these features. Feature selection helps in enhancing the detection rate of the bot traffic in the network. For performing feature selection Principal Components Analysis is chosen. Top ranked features from PCA are added to existing work. Result shows improvement in detection rate and reduction in false positive rate.
引用
收藏
页码:471 / 478
页数:8
相关论文
共 50 条
  • [31] Peer to Peer Botnet Detection Based on Network Traffic Analysis
    Almutairi, Suzan
    Mahfoudh, Saoucene
    Alowibdi, Jalal S.
    2016 8TH IFIP INTERNATIONAL CONFERENCE ON NEW TECHNOLOGIES, MOBILITY AND SECURITY (NTMS), 2016,
  • [32] ACNN-BOT: An Ant Colony Inspired Feature Selection Approach for ANN Based Botnet Detection
    Joshi, Chirag
    Ranjan, Ranjeet K.
    Bharti, Vishal
    WIRELESS PERSONAL COMMUNICATIONS, 2023, 132 (03) : 1999 - 2021
  • [33] Enhancing IoT Botnet Detection through Machine Learning-based Feature Selection and Ensemble Models
    Sharma, Ravi
    Din, Saika Mohi Ud
    Sharma, Nonita
    Kumar, Arun
    EAI ENDORSED TRANSACTIONS ON SCALABLE INFORMATION SYSTEMS, 2024, 11 (02) : 1 - 6
  • [34] Feature selection for IoT botnet detection using equilibrium and Battle Royale Optimization
    Bani Baker, Qanita
    Samarneh, Alaa
    Computers and Security, 2024, 147
  • [35] Machine learning and metaheuristic optimization algorithms for feature selection and botnet attack detection
    Maazalahi, Mahdieh
    Hosseini, Soodeh
    KNOWLEDGE AND INFORMATION SYSTEMS, 2025, : 3549 - 3597
  • [36] Botnet detection based on traffic behavior analysis and flow intervals
    Zhao, David
    Traore, Issa
    Sayed, Bassam
    Lu, Wei
    Saad, Sherif
    Ghorbani, Ali
    Garant, Dan
    COMPUTERS & SECURITY, 2013, 39 : 2 - 16
  • [37] A Review of Botnet Detection Approaches Based on DNS Traffic Analysis
    Al-Mashhadi, Saif
    Anbar, Mohammed
    Karuppayah, Shankar
    Al-Ani, Ahmed K.
    INTELLIGENT AND INTERACTIVE COMPUTING, 2019, 67 : 305 - 321
  • [38] Smart Approach for Botnet Detection Based on Network Traffic Analysis
    Obeidat, Alaa
    Yaqbeh, Rola
    JOURNAL OF ELECTRICAL AND COMPUTER ENGINEERING, 2022, 2022
  • [39] An efficient botnet detection approach based on feature learning and classification
    Padmavathi, B.
    Muthukumar, B.
    JOURNAL OF CONTROL AND DECISION, 2023, 10 (01) : 40 - 53
  • [40] A Technique for the Botnet Detection Based on DNS-Traffic Analysis
    Pomorova, Oksana
    Savenko, Oleg
    Lysenko, Sergii
    Kryshchuk, Andrii
    Bobrovnikova, Kira
    COMPUTER NETWORKS, CN 2015, 2015, 522 : 127 - 138