Javascript must be enabled to continue!
A Hybrid Association Rule-Based Method to Detect and Classify Botnets
View through CrossRef
Nowadays, botnet has become a threat in the area of cybersecurity, and, worse still, it is difficult to be detected in complex network environments. Thus, traffic analysis is adopted to detect the botnet since this kind of method is practical and effective; however, the false rate is very high. The reason is that normal traffic and botnet traffic are quite close to the border, making it so difficult to be recognized. In this paper, we propose an algorithm based on a hybrid association rule to detect and classify the botnets, which can calculate botnets’ boundary traffic features and receive effects in the identification between normal and botnet traffic ideally. First, after collecting the data of different botnets in a laboratory, we analyze botnets traffic features by processing a data mining on it. The suspicious botnet traffic is filtered through DNS protocol, black and white list, and real-time feature filtering methods. Second, we analyze the correlation between domain names and IP addresses. Combining with the advantages of the existing time-based detection methods, we do a global correlation analysis on the characteristics of botnets, to judge whether the detection objects can be botnets according to these indicators. Then, we calculate these parameters, including the support, trust, and membership functions for association rules, to determine which type of botnet it belongs to. Finally, we process the test by using the public dataset and it turns out that the accuracy of our algorithm is higher.
Title: A Hybrid Association Rule-Based Method to Detect and Classify Botnets
Description:
Nowadays, botnet has become a threat in the area of cybersecurity, and, worse still, it is difficult to be detected in complex network environments.
Thus, traffic analysis is adopted to detect the botnet since this kind of method is practical and effective; however, the false rate is very high.
The reason is that normal traffic and botnet traffic are quite close to the border, making it so difficult to be recognized.
In this paper, we propose an algorithm based on a hybrid association rule to detect and classify the botnets, which can calculate botnets’ boundary traffic features and receive effects in the identification between normal and botnet traffic ideally.
First, after collecting the data of different botnets in a laboratory, we analyze botnets traffic features by processing a data mining on it.
The suspicious botnet traffic is filtered through DNS protocol, black and white list, and real-time feature filtering methods.
Second, we analyze the correlation between domain names and IP addresses.
Combining with the advantages of the existing time-based detection methods, we do a global correlation analysis on the characteristics of botnets, to judge whether the detection objects can be botnets according to these indicators.
Then, we calculate these parameters, including the support, trust, and membership functions for association rules, to determine which type of botnet it belongs to.
Finally, we process the test by using the public dataset and it turns out that the accuracy of our algorithm is higher.
Related Results
A STUDY ON ADVANCED BOTNETS DETECTION IN VARIOUS COMPUTING SYSTEMS USING MACHINE LEARNING TECHNIQUES
A STUDY ON ADVANCED BOTNETS DETECTION IN VARIOUS COMPUTING SYSTEMS USING MACHINE LEARNING TECHNIQUES
Due to the rapid growth and use of Emerging technologies such as Artificial Intelligence, Machine Learning and Internet of Things, Information industry became so popular, meanwhile...
An International Rule of Law
An International Rule of Law
The “international rule of law” is an elusive concept. Under this heading, mainly two variations are being discussed: The international rule of law “proper” and an “internationaliz...
Are Cervical Ribs Indicators of Childhood Cancer? A Narrative Review
Are Cervical Ribs Indicators of Childhood Cancer? A Narrative Review
Abstract
A cervical rib (CR), also known as a supernumerary or extra rib, is an additional rib that forms above the first rib, resulting from the overgrowth of the transverse proce...
THE CONCEPT OF HYBRID THREATS
THE CONCEPT OF HYBRID THREATS
In 2016, during the Warsaw summit, NATO and EU reached an agreement to improve the cooperation in the fight against the hybrid threats, describing the security situation in Europe ...
The Rice (Oryza Sativa L.) Rc Gene, Which Imparts Resistance To Pre-Harvest Sprouting, Retains Seed and Milled Rice Quality
The Rice (Oryza Sativa L.) Rc Gene, Which Imparts Resistance To Pre-Harvest Sprouting, Retains Seed and Milled Rice Quality
Abstract
Pre-harvest sprouting (PHS) in cereal crops, including rice ( Oryza sativa L.), causes substantial yield and end-use quality losses worldwide. These losses could b...
Modifikasi Model Rak Alat Pengering Tipe Hybrid Pada Pengeringan Ikan Keumamah
Modifikasi Model Rak Alat Pengering Tipe Hybrid Pada Pengeringan Ikan Keumamah
Abstrak. Pengeringan hybrid merupakan pengeringan yang menggunakan dua atau lebih sumber energi untuk proses penguapan air. Teknologi ini merupakan alternatif teknologi untuk penge...
Tracing the Evolving Scope of the Rule of Reason and the Per Se Rule
Tracing the Evolving Scope of the Rule of Reason and the Per Se Rule
Analysis of alleged antitrust violations in the United States is conducted by generally using one of two rules of decision. Under the rule of reason, the presumptive mode of analys...
Modeling Hybrid Metaheuristic Optimization Algorithm for Convergence Prediction
Modeling Hybrid Metaheuristic Optimization Algorithm for Convergence Prediction
The project aims at the design and development of six hybrid nature inspired algorithms based on Grey Wolf Optimization algorithm with Artificial Bee Colony Optimization algorithm ...

