مرکز اطلاعات علمی Scientific Information Database (SID) - Trusted Source for Research and Academic Resources

Persian Verion

مرکز اطلاعات علمی Scientific Information Database (SID) - Trusted Source for Research and Academic Resources

video

مرکز اطلاعات علمی Scientific Information Database (SID) - Trusted Source for Research and Academic Resources

sound

مرکز اطلاعات علمی Scientific Information Database (SID) - Trusted Source for Research and Academic Resources

Persian Version

مرکز اطلاعات علمی Scientific Information Database (SID) - Trusted Source for Research and Academic Resources

View:

702
مرکز اطلاعات علمی Scientific Information Database (SID) - Trusted Source for Research and Academic Resources

Download:

130
مرکز اطلاعات علمی Scientific Information Database (SID) - Trusted Source for Research and Academic Resources

Cites:

Information Journal Paper

Title

BOT ONUS: AN ONLINE UNSUPERVISED METHOD FOR BOTNET DETECTION

Pages

  51-62

Abstract

 Botnets are recognized as one of the most dangerous threats to the Internet infrastructure. They are used for malicious activities such as launching distributed denial of service attacks, sending spam, and leaking personal information. Existing BOTNET DETECTION methods produce a number of good ideas, but they are far from complete yet, since most of them cannot detect botnets in an early stage of their lifecycle; moreover, they depend on a particular command and control (C&C) protocol. In this paper, we address these issues and propose an online unsupervised method, called BotOnus, for BOTNET DETECTION that does not require a priori knowledge of botnets. It extracts a set of flow feature vectors from the network traffic at the end of each time period, and then groups them to some flow clusters by a novel online fixed-width clustering algorithm. Flow clusters that have at least two members, and their intra-cluster similarity is above a similarity threshold, are identified as suspicious botnet clusters, and all hosts in such clusters are identi ed as bot infected. We demonstrate the effectiveness of BotOnus to detect various botnets including HTTP-, IRC-, and P2P-based botnets using a testbed network. The results of experiments show that it can successfully detect various botnets with an average detection rate of 94: 33% and an average false alarm rate of 3: 74%.

Cites

  • No record.
  • References

  • No record.
  • Cite

    APA: Copy

    YAHYAZADEH, MOSA, & ABADI, MAHDI. (2012). BOT ONUS: AN ONLINE UNSUPERVISED METHOD FOR BOTNET DETECTION. THE ISC INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 4(1), 51-62. SID. https://sid.ir/paper/241818/en

    Vancouver: Copy

    YAHYAZADEH MOSA, ABADI MAHDI. BOT ONUS: AN ONLINE UNSUPERVISED METHOD FOR BOTNET DETECTION. THE ISC INTERNATIONAL JOURNAL OF INFORMATION SECURITY[Internet]. 2012;4(1):51-62. Available from: https://sid.ir/paper/241818/en

    IEEE: Copy

    MOSA YAHYAZADEH, and MAHDI ABADI, “BOT ONUS: AN ONLINE UNSUPERVISED METHOD FOR BOTNET DETECTION,” THE ISC INTERNATIONAL JOURNAL OF INFORMATION SECURITY, vol. 4, no. 1, pp. 51–62, 2012, [Online]. Available: https://sid.ir/paper/241818/en

    Related Journal Papers

    Related Seminar Papers

  • No record.
  • Related Plans

  • No record.
  • Recommended Workshops






    Move to top
    telegram sharing button
    whatsapp sharing button
    linkedin sharing button
    twitter sharing button
    email sharing button
    email sharing button
    email sharing button
    sharethis sharing button