Tracking Temporal Evolution of Network Activity for Botnet Detection

08/09/2019
by   Kapil Sinha, et al.
0

Botnets are becoming increasingly prevalent as the primary enabling technology in a variety of malicious campaigns such as email spam, click fraud, distributed denial-of-service (DDoS) attacks, and cryptocurrency mining. Botnet technology has continued to evolve rapidly making detection a very challenging problem. There is a fundamental need for robust detection methods that are insensitive to characteristics of a specific botnet and are generalizable across different botnet types. We propose a novel supervised approach to detect malicious botnet hosts by tracking a host's network activity over time using a Long Short-Term Memory (LSTM) based neural network architecture. We build a prototype to demonstrate the feasibility of our approach, evaluate it on the CTU-13 dataset, and compare our performance against existing detection methods. We show that our approach results in a more generalizable, botnet-agnostic detection methodology, is amenable to real-time implementation, and performs well compared to existing approaches, with an overall accuracy score of 96.2

READ FULL TEXT
research
08/26/2020

SIGL: Securing Software Installations Through Deep Graph Learning

Many users implicitly assume that software can only be exploited after i...
research
10/26/2020

Malicious Requests Detection with Improved Bidirectional Long Short-term Memory Neural Networks

Detecting and intercepting malicious requests are one of the most widely...
research
08/13/2020

Detecting Abnormal Traffic in Large-Scale Networks

With the rapid technological advancements, organizations need to rapidly...
research
10/30/2019

Neural networks trained with WiFi traces to predict airport passenger behavior

The use of neural networks to predict airport passenger activity choices...
research
03/19/2022

Reflective Fiber Faults Detection and Characterization Using Long-Short-Term Memory

To reduce operation-and-maintenance expenses (OPEX) and to ensure optica...
research
09/05/2021

A Transformer-based Model to Detect Phishing URLs

Phishing attacks are among emerging security issues that recently draws ...
research
08/27/2021

Modeling and Analyzing Attacker Behavior in IoT Botnet using Temporal Convolution Network (TCN)

Traditional reactive approach of blacklisting botnets fails to adapt to ...

Please sign up or login with your details

Forgot password? Click here to reset