首页> 外文期刊>Journal of Big Data >Botnet detection using graph-based feature clustering
【24h】

Botnet detection using graph-based feature clustering

机译:使用基于图的特征聚类进行僵尸网络检测

获取原文

摘要

Detecting botnets in a network is crucial because bots impact numerous areas such as cyber security, finance, health care, law enforcement, and more. Botnets are becoming more sophisticated and dangerous day-by-day, and most of the existing rule based and flow based detection methods may not be capable of detecting bot activities in an efficient and effective manner. Hence, designing a robust and fast botnet detection method is of high significance. In this study, we propose a novel botnet detection methodology based on topological features of nodes within a graph: in degree, out degree, in degree weight, out degree weight, clustering coefficient, node betweenness, and eigenvector centrality. A self-organizing map clustering method is applied to establish clusters of nodes in the network based on these features. Our method is capable of isolating bots in clusters of small sizes while containing the majority of normal nodes in the same big cluster. Thus, bots can be detected by searching a limited number of nodes. A filtering procedure is also developed to further enhance the algorithm efficiency by removing inactive nodes from consideration. The methodology is verified using the CTU-13 datasets, and benchmarked against a classification-based detection method. The results show that our proposed method can efficiently detect the bots despite their varying behaviors.
机译:检测网络中的僵尸网络至关重要,因为僵尸网络会影响众多领域,例如网络安全,金融,医疗保健,执法等。僵尸网络正变得越来越复杂和危险,并且大多数现有的基于规则和基于流的检测方法可能无法有效地检测到僵尸活动。因此,设计一种鲁棒,快速的僵尸网络检测方法具有重要意义。在这项研究中,我们提出了一种基于图中节点的拓扑特征的新颖的僵尸网络检测方法:度,度,权重,度权,聚类系数,节点间性和特征向量中心度。基于这些特征,采用了一种自组织的地图聚类方法来建立网络中节点的聚类。我们的方法能够隔离小型群集中的机器人,同时在同一大型群集中包含大多数正常节点。因此,可以通过搜索有限数量的节点来检测机器人。还开发了一种过滤程序,通过从考虑中删除不活动的节点来进一步提高算法效率。使用CTU-13数据集验证了该方法,并针对基于分类的检测方法进行了基准测试。结果表明,我们提出的方法可以有效地检测机器人,尽管它们的行为各不相同。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号