TY - JOUR
T1 - B-Corr Model for Bot Group Activity Detection Based on Network Flows Traffic Analysis
AU - Hostiadi, Dandy Pramana
AU - Wibisono, Waskitho
AU - Ahmad, Tohari
N1 - Publisher Copyright:
Copyright © 2020 KSII
PY - 2020/10/31
Y1 - 2020/10/31
N2 - Botnet is a type of dangerous malware. Botnet attack with a collection of bots attacking a similar target and activity pattern is called bot group activities. The detection of bot group activities using intrusion detection models can only detect single bot activities but cannot detect bots' behavioral relation on bot group attack. Detection of bot group activities could help network administrators isolate an activity or access a bot group attacks and determine the relations between bots that can measure the correlation. This paper proposed a new model to measure the similarity between bot activities using the intersections-probability concept to define bot group activities called as B-Corr Model. The B-Corr model consisted of several stages, such as extraction feature from bot activity flows, measurement of intersections between bots, and similarity value production. B-Corr model categorizes similar bots with a similar target to specify bot group activities. To achieve a more comprehensive view, the B-Corr model visualizes the similarity values between bots in the form of a similar bot graph. Furthermore, extensive experiments have been conducted using real botnet datasets with high detection accuracy in various scenarios.
AB - Botnet is a type of dangerous malware. Botnet attack with a collection of bots attacking a similar target and activity pattern is called bot group activities. The detection of bot group activities using intrusion detection models can only detect single bot activities but cannot detect bots' behavioral relation on bot group attack. Detection of bot group activities could help network administrators isolate an activity or access a bot group attacks and determine the relations between bots that can measure the correlation. This paper proposed a new model to measure the similarity between bot activities using the intersections-probability concept to define bot group activities called as B-Corr Model. The B-Corr model consisted of several stages, such as extraction feature from bot activity flows, measurement of intersections between bots, and similarity value production. B-Corr model categorizes similar bots with a similar target to specify bot group activities. To achieve a more comprehensive view, the B-Corr model visualizes the similarity values between bots in the form of a similar bot graph. Furthermore, extensive experiments have been conducted using real botnet datasets with high detection accuracy in various scenarios.
KW - Bot activity flows
KW - Bot group activity
KW - Intrusion detection system
KW - Network security
KW - Similar intersection
UR - http://www.scopus.com/inward/record.url?scp=85095962705&partnerID=8YFLogxK
U2 - 10.3837/tiis.2020.10.014
DO - 10.3837/tiis.2020.10.014
M3 - Article
AN - SCOPUS:85095962705
SN - 1976-7277
VL - 14
SP - 4176
EP - 4197
JO - KSII Transactions on Internet and Information Systems
JF - KSII Transactions on Internet and Information Systems
IS - 10
ER -