Botnet detection based on network flow analysis using inverse statistics

2022 17th Iberian Conference on Information Systems and Technologies (CISTI)(2022)

引用 1|浏览0
暂无评分
摘要
A botnet is a network of infected computers, which are remotely controlled by a cybercriminal, called botmaster, which aims to carry out massive cyberattacks, such as DDoS, SPAM, and information theft. Traditional botnet detection methods, usually signature-based, are unable to detect unknown botnets. The behavior-based analysis is promising for detecting current botnet trends, which are constantly evolving. This article proposes an exploration analysis of botnet detection mechanisms based on the network flow behavior. The main technique used to detect botnets was recently developed and is called Energy-based Flow Classifier (EFC). This technique uses inverse statistics to detect anomalies. Two heterogeneous datasets, CTU-13 and ISOT HTTP were used to evaluate the efficiency of the generated model and the results were compared with several traditional classifiers, of one and two classes. The results obtained show that EFC obtained more stable results, regardless of the domain, unlike the other tested algorithms.
更多
查看译文
关键词
botnet, network flow, anomaly detection, inverse statistics
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要