8Rule-Based Approach for Botnet Behavior Analysis

Supriya Raheja1*, Geetika Munjal1, Jyoti Jangra2 and Rakesh Garg1

1Department of Computer Science & Enginerring, Amity University, Noida, India

2IBM India Pvt. Ltd, Gurugram, India

Abstract

Botnets pose as serious threat and huge loss to organizations. The presence of botnet traffic in any network is a matter of serious concern. They are used for many activities of malicious type like distributed denial of service (DDOS) attacks, mass spam, phishing attack, click frauds, stealing the user’s confidential information like passwords and other types of cyber-crimes. The detection of botnets in early phases is very crucial for minimizing the damage. With this aim, the proposed approach uses Network forensic analysis flow exporter tools like Wireshark, NetworkMiner and CapLoader for analyzing and extraction of important features. The botnet traffic flows are analyzed based on the features set extracted by these tools. The impacts of these extracted features are studied with respect to the Botnet malicious activities. A botnet detection model is generated using decision tree. The performance of different algorithms namely Decision Tree, Naïve Bayes and ZeroR are analyzed. It has been observed that the decision tree works better with selective features.

Keywords: Bots, botnet behavior, traffic flow exporter tools, malware, machine learning, cross validation, botnet traffic flow

8.1 Introduction

Today’s internet world is rapidly growing ...

Get Intelligent Data Analytics for Terror Threat Prediction now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.