Afficher la notice abrégée
| dc.rights.license |
CC BY |
eng |
| dc.contributor.author |
Ibrahim, Wan Nur Hidayah |
cze |
| dc.contributor.author |
Anuar, Syahid |
cze |
| dc.contributor.author |
Selamat, Ali Bin |
cze |
| dc.contributor.author |
Krejcar, Ondřej |
cze |
| dc.contributor.author |
Gonzalez Crespo, Ruben |
cze |
| dc.contributor.author |
Herrera-Viedma, Enrique |
cze |
| dc.contributor.author |
Fujita, Hamido |
cze |
| dc.date.accessioned |
2026-07-21T06:19:15Z |
|
| dc.date.available |
2026-07-21T06:19:15Z |
|
| dc.date.issued |
2021 |
eng |
| dc.identifier.issn |
2169-3536 |
eng |
| dc.identifier.uri |
http://hdl.handle.net/20.500.12603/2742 |
|
| dc.description.abstract |
A botnet is a malware program that a hacker remotely controls called a botmaster. Botnet can perform massive cyber-attacks such as DDOS, SPAM, click-fraud, information, and identity stealing. The botnet also can avoid being detected by a security system. The traditional method of detecting botnets commonly used signature-based analysis unable to detect unseen botnets. The behavior-based analysis seems like a promising solution to the current trends of botnets that keep evolving. This paper proposes a multilayer framework for botnet detection using machine learning algorithms that consist of a filtering module and classification module to detect the botnet's command and control server. We highlighted several criteria for our framework, such as it must be structure-independent, protocol-independent, and able to detect botnet in encapsulated technique. We used behavior-based analysis through flow-based features that analyzed the packet header by aggregating it to a 1-s time. This type of analysis enables detection if the packet is encapsulated, such as using a VPN tunnel. We also extend the experiment using different time intervals, but a 1-s time interval shows the most impressive results. The result shows that our botnet detection method can detect up to 92% of the f-score, and the lowest false-negative rate was 1.5%. |
eng |
| dc.format |
p. 48753-48768 |
eng |
| dc.language.iso |
eng |
eng |
| dc.publisher |
IEEE-INST ELECTRICAL ELECTRONICS ENGINEERS INC |
eng |
| dc.relation.ispartof |
IEEE Access, volume 9, issue: February |
eng |
| dc.subject |
Botnet |
eng |
| dc.subject |
Servers |
eng |
| dc.subject |
Malware |
eng |
| dc.subject |
Command and control systems |
eng |
| dc.subject |
Security |
eng |
| dc.subject |
Encryption |
eng |
| dc.subject |
Virtual private networks |
eng |
| dc.subject |
Behavior-based analysis |
eng |
| dc.subject |
botnet |
eng |
| dc.subject |
flow-based feature selection |
eng |
| dc.subject |
k-nearest neighbor |
eng |
| dc.subject |
structure independent |
eng |
| dc.title |
Multilayer Framework for Botnet Detection Using Machine Learning Algorithms |
eng |
| dc.type |
article |
eng |
| dc.identifier.obd |
43877598 |
eng |
| dc.identifier.wos |
000637188400001 |
eng |
| dc.identifier.doi |
10.1109/ACCESS.2021.3060778 |
eng |
| dc.publicationstatus |
postprint |
eng |
| dc.peerreviewed |
yes |
eng |
| dc.source.url |
https://ieeexplore.ieee.org/abstract/document/9359784 |
cze |
| dc.relation.publisherversion |
https://ieeexplore.ieee.org/abstract/document/9359784 |
eng |
| dc.rights.access |
Open Access |
eng |
Fichier(s) constituant ce document
Ce document figure dans la(les) collection(s) suivante(s)
Afficher la notice abrégée