Feature Selection for Effective Botnet Detection Based on Periodicity of Traffic

被引:1
|
作者
Harsha, T. [1 ]
Asha, S. [1 ]
Soniya, B. [1 ]
机构
[1] SCT Coll Engn, Dept Comp Sci & Engn, Trivandrum, Kerala, India
来源
INFORMATION SYSTEMS SECURITY | 2016年 / 10063卷
关键词
Botnet; C&C server; Periodicity; Bot; HTTP;
D O I
10.1007/978-3-319-49806-5_26
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Botnets are networks that are composed with a set of compromised machines called bots that are remotely controlled by a botmaster. They pose a threatening remark to network communications and applications. A botnet relies on its command and control communication channel for performing attacks. C2 traffic occurs prior to any attack; hence, the detection of botnet's traffic helps in detecting the bots before any real attack happens. Recently, the HTTP based Botnet threat has become a serious challenge for security experts as Bots can be distributed quickly and stealthily. The HTTP Bots periodically connect to particular web pages or URLs to get commands and updates from the Botmaster. In fact, this identifiable periodic connection pattern has been used to detect HTTP Botnets. This paper proposes an idea for identifying bots that exhibit non periodic nature as well normal traffic that exhibit periodic nature. The proposed method reduces the false positive rate as well as increases the detection rate. For that a set of traffic features are taken from many detection methods and feature selection is made on these features. Feature selection helps in enhancing the detection rate of the bot traffic in the network. For performing feature selection Principal Components Analysis is chosen. Top ranked features from PCA are added to existing work. Result shows improvement in detection rate and reduction in false positive rate.
引用
收藏
页码:471 / 478
页数:8
相关论文
共 50 条
  • [41] Flow Based Botnet Traffic Detection Using Machine Learning
    Gahelot, Parul
    Dayal, Neelam
    PROCEEDINGS OF ICETIT 2019: EMERGING TRENDS IN INFORMATION TECHNOLOGY, 2020, 605 : 418 - 426
  • [42] Combining MIC Feature Selection and Feature-based MSPCA for Network Traffic Anomaly Detection
    Chen, Zhaomin
    Yeo, Chai Kiat
    Francis, Bu Sung Lee
    Lau, Chiew Tong
    2016 THIRD INTERNATIONAL CONFERENCE ON DIGITAL INFORMATION PROCESSING, DATA MINING, AND WIRELESS COMMUNICATIONS (DIPDMWC), 2016, : 176 - 181
  • [43] The effects of feature selection on the classification of encrypted botnet
    Zahian Ismail
    Aman Jantan
    Mohd. Najwadi Yusoff
    Muhammad Ubale Kiru
    Journal of Computer Virology and Hacking Techniques, 2021, 17 : 61 - 74
  • [44] Botnet detection using graph-based feature clustering
    Chowdhury S.
    Khanzadeh M.
    Akula R.
    Zhang F.
    Zhang S.
    Medal H.
    Marufuzzaman M.
    Bian L.
    Journal of Big Data, 4 (1)
  • [45] The effects of feature selection on the classification of encrypted botnet
    Ismail, Zahian
    Jantan, Aman
    Yusoff, Mohd. Najwadi
    Kiru, Muhammad Ubale
    JOURNAL OF COMPUTER VIROLOGY AND HACKING TECHNIQUES, 2021, 17 (01) : 61 - 74
  • [46] Centralized Botnet Detection by Traffic Aggregation
    Wang, Tao
    Yu, Shun-Zheng
    2009 IEEE INTERNATIONAL SYMPOSIUM ON PARALLEL AND DISTRIBUTED PROCESSING WITH APPLICATIONS, PROCEEDINGS, 2009, : 86 - 93
  • [47] IRC traffic analysis for botnet detection
    Mazzariello, Claudio
    FOURTH INTERNATIONAL SYMPOSIUM ON INFORMATION ASSURANCE AND SECURITY, PROCEEDINGS, 2008, : 318 - 323
  • [48] Detection of Botnet traffic by using Neuro-fuzzy based Intrusion Detection
    Pradeepthi, K., V
    Kannan, A.
    2018 10TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING (ICOAC), 2018, : 118 - 123
  • [49] An Intelligent Fuzzy Rule based Feature Selection for Effective Intrusion Detection
    Riyaz, B.
    Ganapathy, S.
    PROCEEDINGS OF THE 2018 INTERNATIONAL CONFERENCE ON RECENT TRENDS IN ADVANCED COMPUTING (ICRTAC-CPS 2018), 2018, : 206 - 211
  • [50] Abnormal Traffic Detection Based on Generative Adversarial Network and Feature Optimization Selection
    Ma, Wengang
    Zhang, Yadong
    Guo, Jin
    Li, Kehong
    INTERNATIONAL JOURNAL OF COMPUTATIONAL INTELLIGENCE SYSTEMS, 2021, 14 (01) : 1170 - 1188