Detailed Information

Cited 3 time in webofscience Cited 5 time in scopus
Metadata Downloads

Cluster Ensemble with Link-Based Approach for Botnet Detection

Authors
Mai, L.Noh, D.K.
Issue Date
Jul-2018
Publisher
Springer New York LLC
Keywords
Cyber crime; Intrusion detection system; Network flow; Machine learning; Classification; Command and control
Citation
Journal of Network and Systems Management, v.26, no.3, pp.1 - 24
Journal Title
Journal of Network and Systems Management
Volume
26
Number
3
Start Page
1
End Page
24
URI
http://scholarworks.bwise.kr/ssu/handle/2018.sw.ssu/7371
DOI
10.1007/s10922-017-9436-x
ISSN
1064-7570
Abstract
Botnet detection is one of the most imminent tasks for cyber security. Among popular botnet countermeasures, an intrusion detection system is the prominent mechanism. In the past, packet-based intrusion detection systems were popular. However, flow-based intrusion detection systems have been preferred in recent years due to their ability to adapt to modern high-speed networks. A collection of flows from an enterprise network usually contains both botnet traffic and normal traffic. To classify this traffic, supervised machine learning algorithms, i.e., classifications, have been applied and achieved a high accuracy. In an effort to improve the ability of intrusion detection systems against botnets, some studies have suggested partitioning flows into clusters before applying the classifications and this step could significantly reduce the complexity of a flow set. However, the instability of individual clustering algorithms is still a constraint for botnet detection.To overcome this bottleneck, we propose a novel method that combines individual partitions to become a strong learner through the use of a link-based algorithm. Our experiments show that our cluster ensemble model outperforms existing botnet detection mechanisms with a high reliability. We also determine the balance between accuracy and computer resources for botnet detection, and thereby propose a range for the maximum duration time of flows in botnet research. © 2017 Springer Science+Business Media, LLC
Files in This Item
There are no files associated with this item.
Appears in
Collections
College of Information Technology > Department of Smart Systems Software > 1. Journal Articles

qrcode

Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.

Related Researcher

Researcher Noh, Dong Kun photo

Noh, Dong Kun
College of Information Technology (Department of Smart Systems Software)
Read more

Altmetrics

Total Views & Downloads

BROWSE