BotMark: Automated botnet detection with hybrid analysis of flow-based and graph-based traffic behaviors.

Information Sciences(2020)

引用 137|浏览101
暂无评分
摘要
•BotMark automatically detects bots with hybrid analysis of flow-based and graph-based traffic behaviors.•Botmark is independent of C&C protocols and structures, requires no a priori knowledge of botnets, and can be adopted in complex environments.•15 flow-based features and 3 types of graph-based features are extracted from network traffic to characterize the behaviors of botnets.•We collect a large size of network traffic by simulating 5 botnets in a real computing environment and share the data.•BotMark reaches the detection accuracy of 99.94% with hybrid analysis.
更多
查看译文
关键词
Botnet detection,Network security,Intrusion detection,Network monitoring,Machine learning
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要