Deep fused flow and topology features for botnet detection basing on pretrained GCN

07/20/2023
by   Meng Xiaoyuan, et al.
0

Nowadays, botnets have become one of the major threats to cyber security. The characteristics of botnets are mainly reflected in bots network behavior and their intercommunication relationships. Existing botnet detection methods use flow features or topology features individually, which overlook the other type of feature. This affects model performance. In this paper, we propose a botnet detection model which uses graph convolutional network (GCN) to deeply fuse flow features and topology features for the first time. We construct communication graphs from network traffic and represent nodes with flow features. Due to the imbalance of existing public traffic flow datasets, it is impossible to train a GCN model on these datasets. Therefore, we use a balanced public communication graph dataset to pretrain a GCN model, thereby guaranteeing its capacity for identify topology features. We then feed the communication graph with flow features into the pretrained GCN. The output from the last hidden layer is treated as the fusion of flow and topology features. Additionally, by adjusting the number of layers in the GCN network, the model can effectively detect botnets under both C2 and P2P structures. Validated on the public ISCX2014 dataset, our approach achieves a remarkable recall rate 92.90 F1-score of 92.35 effectiveness of our method, but also outperform the performance of the currently leading detection models.

READ FULL TEXT

page 10

page 24

research
04/05/2021

Label-GCN: An Effective Method for Adding Label Propagation to Graph Convolutional Networks

We show that a modification of the first layer of a Graph Convolutional ...
research
02/17/2022

Exploring Human Mobility for Multi-Pattern Passenger Prediction: A Graph Learning Framework

Traffic flow prediction is an integral part of an intelligent transporta...
research
05/22/2019

Simulation and Augmentation of Social Networks for Building Deep Learning Models

A limitation of the Graph Convolutional Networks (GCN) is that it assume...
research
10/23/2019

Relation Modeling with Graph Convolutional Networks for Facial Action Unit Detection

Most existing AU detection works considering AU relationships are relyin...
research
10/23/2020

BiTe-GCN: A New GCN Architecture via BidirectionalConvolution of Topology and Features on Text-Rich Networks

Graph convolutional networks (GCNs), aiming to integrate high-order neig...
research
07/03/2023

Node-weighted Graph Convolutional Network for Depression Detection in Transcribed Clinical Interviews

We propose a simple approach for weighting self-connecting edges in a Gr...
research
07/28/2021

Inferring Multiple Relationships between ASes using Graph Convolutional Network

Precisely understanding the business relationships between Autonomous Sy...

Please sign up or login with your details

Forgot password? Click here to reset