Network Security Modeling using NetFlow Data: Detecting Botnet attacks in IP Traffic

08/19/2021
by   Ganesh Subramaniam, et al.
0

Cybersecurity, security monitoring of malicious events in IP traffic, is an important field largely unexplored by statisticians. Computer scientists have made significant contributions in this area using statistical anomaly detection and other supervised learning methods to detect specific malicious events. In this research, we investigate the detection of botnet command and control (C C) hosts in massive IP traffic. We use the NetFlow data, the industry standard for monitoring of IP traffic for exploratory analysis and extracting new features. Using statistical as well as deep learning models, we develop a statistical intrusion detection system (SIDS) to predict traffic traces identified with malicious attacks. Employing interpretative machine learning techniques, botnet traffic signatures are derived. These models successfully detected botnet C C hosts and compromised devices. The results were validated by matching predictions to existing blacklists of published malicious IP addresses.

READ FULL TEXT

page 6

page 9

page 13

page 14

research
11/24/2022

Network Security Modelling with Distributional Data

We investigate the detection of botnet command and control (C2) hosts in...
research
10/23/2019

Intranet Security using a LAN Packet Sniffer to Monitor Traffic

This paper was designed to provide Intranet traffic monitoring by sniffi...
research
04/13/2018

RIPEx: Extracting malicious IP addresses from security forums using cross-forum learning

Is it possible to extract malicious IP addresses reported in security fo...
research
06/28/2018

Detecting Port and Net Scan using Apache Spark

Today, due to the high number of attacks and of anomalous events in netw...
research
04/05/2022

Detecting Cloud-Based Phishing Attacks by Combining Deep Learning Models

Web-based phishing attacks nowadays exploit popular cloud web hosting se...
research
06/06/2019

Degree-based Outlier Detection within IP Traffic Modelled as a Link Stream

This paper aims at precisely detecting and identifying anomalous events ...
research
10/04/2020

DNS Covert Channel Detection via Behavioral Analysis: a Machine Learning Approach

Detecting covert channels among legitimate traffic represents a severe c...

Please sign up or login with your details

Forgot password? Click here to reset