Exploring a Service-Based Normal Behaviour Profiling System for Botnet Detection
dc.contributor.author | Chen, Weikeng | |
dc.contributor.author | Luo, Xiao | |
dc.contributor.author | Zincir-Heywood, A. Nur | |
dc.contributor.department | Computer Information and Graphics Technology, School of Engineering and Technology | en_US |
dc.date.accessioned | 2018-05-03T15:28:22Z | |
dc.date.available | 2018-05-03T15:28:22Z | |
dc.date.issued | 2017-05 | |
dc.description.abstract | Effective detection of botnet traffic becomes difficult as the attackers use encrypted payload and dynamically changing port numbers (protocols) to bypass signature based detection and deep packet inspection. In this paper, we build a normal profiling-based botnet detection system using three unsupervised learning algorithms on service-based flow-based data, including self-organizing map, local outlier, and k-NN outlier factors. Evaluations on publicly available botnet data sets show that the proposed system could reach up to 91% detection rate with a false alarm rate of 5%. | en_US |
dc.eprint.version | Author's manuscript | en_US |
dc.identifier.citation | Chen, W., Luo, X., & Zincir-Heywood, A. N. (2017). Exploring a service-based normal behaviour profiling system for botnet detection. In 2017 IFIP/IEEE Symposium on Integrated Network and Service Management (IM) (pp. 947–952). https://doi.org/10.23919/INM.2017.7987417 | en_US |
dc.identifier.uri | https://hdl.handle.net/1805/16010 | |
dc.language.iso | en | en_US |
dc.publisher | IEEE | en_US |
dc.relation.isversionof | 10.23919/INM.2017.7987417 | en_US |
dc.relation.journal | 2017 IFIP/IEEE Symposium on Integrated Network and Service Management | en_US |
dc.rights | Publisher Policy | en_US |
dc.source | Author | en_US |
dc.subject | botnet traffic | en_US |
dc.subject | protocols | en_US |
dc.subject | botnet detection | en_US |
dc.title | Exploring a Service-Based Normal Behaviour Profiling System for Botnet Detection | en_US |
dc.type | Conference proceedings | en_US |