A novel Machine Learning-based approach for the detection of SSH botnet infection

被引:15
|
作者
Martinez Garre, Jose Tomas [1 ]
Gil Perez, Manuel [1 ]
Ruiz-Martinez, Antonio [1 ]
机构
[1] Univ Murcia, Dept Informat & Commun Engn, Murcia 30100, Spain
基金
欧盟地平线“2020”;
关键词
Botnet; Machine learning; Zero-day malware; Honeypot; High interaction;
D O I
10.1016/j.future.2020.09.004
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Botnets are causing severe damages to users, companies, and governments through information theft, abuse of online services, DDoS attacks, etc. Although significant research is being made to detect them and mitigate their effect, they are exponentially increasing due to new zero-day attacks, a variation of their behavior, and obfuscation techniques. High Interaction Honeypots (HIH) are the only honeypots able to capture attacks and log all the information generated by attackers when setting up a botnet. The data generated is being processed using Machine Learning (ML) techniques for detection since they can detect hidden patterns. However, so far, research has been focused on intermediate phases of the botnet's life cycle during operation, underestimating the initial phase of infection. To the best of our knowledge, this is the first solution in the infection phase of SSH-based botnets. Therefore, we have designed an approach based on an SSH-based HIH to generate a dataset consisting of executed commands and network information. Herein, we have applied ML techniques for the development of a real-time detection model. This approach reached a very high level of prediction and zero false negatives. Indeed, our system detected all known and unknown SSH sessions intended to infect our honeypots. Thus, our research has demonstrated that new SSH infections can be detected through ML techniques. (C) 2020 Elsevier B.V. All rights reserved.
引用
收藏
页码:387 / 396
页数:10
相关论文
共 50 条
  • [31] Botnet Detection using Machine Learning
    Haq, Shamsul
    Singh, Yashwant
    2018 FIFTH INTERNATIONAL CONFERENCE ON PARALLEL, DISTRIBUTED AND GRID COMPUTING (IEEE PDGC), 2018, : 240 - 245
  • [32] Dimensionality Reduction for Machine Learning Based IoT Botnet Detection
    Bahsi, Hayretdin
    Nomm, Sven
    La Torre, Fabio Benedetto
    2018 15TH INTERNATIONAL CONFERENCE ON CONTROL, AUTOMATION, ROBOTICS AND VISION (ICARCV), 2018, : 1857 - 1862
  • [33] Flow Based Botnet Traffic Detection Using Machine Learning
    Gahelot, Parul
    Dayal, Neelam
    PROCEEDINGS OF ICETIT 2019: EMERGING TRENDS IN INFORMATION TECHNOLOGY, 2020, 605 : 418 - 426
  • [34] Detection of Username Enumeration Attack on SSH Protocol: Machine Learning Approach
    Agghey, Abel Z.
    Mwinuka, Lunodzo J.
    Pandhare, Sanket M.
    Dida, Mussa A.
    Ndibwile, Jema D.
    SYMMETRY-BASEL, 2021, 13 (11):
  • [35] Android botnet detection using machine learning models based on a comprehensive static analysis approach
    Hijawi, Wadi'
    Alqatawna, Ja'far
    Al-Zoubi, Ala' M.
    Hassonah, Mohammad A.
    Faris, Hossam
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2021, 58
  • [36] Predictive machine learning-based integrated approach for DDoS detection and prevention
    Solomon Damena Kebede
    Basant Tiwari
    Vivek Tiwari
    Kamlesh Chandravanshi
    Multimedia Tools and Applications, 2022, 81 : 4185 - 4211
  • [37] Anomaly Detection for Hydroelectric Power Plants: a Machine Learning-based Approach
    Fanan, Mattia
    Baron, Claudio
    Carli, Ruggero
    Divernois, Marc-Aurele
    Marongiu, Jean-Christophe
    Susto, Gian Antonio
    2023 IEEE 21ST INTERNATIONAL CONFERENCE ON INDUSTRIAL INFORMATICS, INDIN, 2023,
  • [38] Predictive machine learning-based integrated approach for DDoS detection and prevention
    Kebede, Solomon Damena
    Tiwari, Basant
    Tiwari, Vivek
    Chandravanshi, Kamlesh
    MULTIMEDIA TOOLS AND APPLICATIONS, 2022, 81 (03) : 4185 - 4211
  • [39] Real-time machine learning-based approach for pothole detection
    Egaji, Oche Alexander
    Evans, Gareth
    Griffiths, Mark Graham
    Islas, Gregory
    EXPERT SYSTEMS WITH APPLICATIONS, 2021, 184
  • [40] A Novel Machine Learning-Based Approach for Fault Detection and Location in Low-Voltage DC Microgrids
    Salehimehr, Sirus
    Miraftabzadeh, Seyed Mahdi
    Brenna, Morris
    SUSTAINABILITY, 2024, 16 (07)