| dc.rights.license | CC BY | eng |
| dc.contributor.author | Ibrahim, Wan Nur Hidayah | cze |
| dc.contributor.author | Anuar, Syahid | cze |
| dc.contributor.author | Selamat, Ali Bin | cze |
| dc.contributor.author | Krejcar, Ondřej | cze |
| dc.contributor.author | Gonzalez Crespo, Ruben | cze |
| dc.contributor.author | Herrera-Viedma, Enrique | cze |
| dc.contributor.author | Fujita, Hamido | cze |
| dc.date.accessioned | 2026-07-21T06:19:15Z | |
| dc.date.available | 2026-07-21T06:19:15Z | |
| dc.date.issued | 2021 | eng |
| dc.identifier.issn | 2169-3536 | eng |
| dc.identifier.uri | http://hdl.handle.net/20.500.12603/2742 | |
| dc.description.abstract | A botnet is a malware program that a hacker remotely controls called a botmaster. Botnet can perform massive cyber-attacks such as DDOS, SPAM, click-fraud, information, and identity stealing. The botnet also can avoid being detected by a security system. The traditional method of detecting botnets commonly used signature-based analysis unable to detect unseen botnets. The behavior-based analysis seems like a promising solution to the current trends of botnets that keep evolving. This paper proposes a multilayer framework for botnet detection using machine learning algorithms that consist of a filtering module and classification module to detect the botnet's command and control server. We highlighted several criteria for our framework, such as it must be structure-independent, protocol-independent, and able to detect botnet in encapsulated technique. We used behavior-based analysis through flow-based features that analyzed the packet header by aggregating it to a 1-s time. This type of analysis enables detection if the packet is encapsulated, such as using a VPN tunnel. We also extend the experiment using different time intervals, but a 1-s time interval shows the most impressive results. The result shows that our botnet detection method can detect up to 92% of the f-score, and the lowest false-negative rate was 1.5%. | eng |
| dc.format | p. 48753-48768 | eng |
| dc.language.iso | eng | eng |
| dc.publisher | IEEE-INST ELECTRICAL ELECTRONICS ENGINEERS INC | eng |
| dc.relation.ispartof | IEEE Access, volume 9, issue: February | eng |
| dc.subject | Botnet | eng |
| dc.subject | Servers | eng |
| dc.subject | Malware | eng |
| dc.subject | Command and control systems | eng |
| dc.subject | Security | eng |
| dc.subject | Encryption | eng |
| dc.subject | Virtual private networks | eng |
| dc.subject | Behavior-based analysis | eng |
| dc.subject | botnet | eng |
| dc.subject | flow-based feature selection | eng |
| dc.subject | k-nearest neighbor | eng |
| dc.subject | structure independent | eng |
| dc.title | Multilayer Framework for Botnet Detection Using Machine Learning Algorithms | eng |
| dc.type | article | eng |
| dc.identifier.obd | 43877598 | eng |
| dc.identifier.wos | 000637188400001 | eng |
| dc.identifier.doi | 10.1109/ACCESS.2021.3060778 | eng |
| dc.publicationstatus | postprint | eng |
| dc.peerreviewed | yes | eng |
| dc.source.url | https://ieeexplore.ieee.org/abstract/document/9359784 | cze |
| dc.relation.publisherversion | https://ieeexplore.ieee.org/abstract/document/9359784 | eng |
| dc.rights.access | Open Access | eng |