TY - GEN
T1 - Enhancing Botnet SPAM Detection Through a Robust Ensemble Classification Approach
AU - Susanto, Frederick Yonatan
AU - Ahmad, Tohari
AU - Hostiadi, Dandy Pramana
AU - Putra, Muhammad Aidiel Rachman
N1 - Publisher Copyright:
© The Author(s), under exclusive license to Springer Nature Singapore Pte Ltd. 2025.
PY - 2025
Y1 - 2025
N2 - Botnet SPAM activities on networks require effective management due to their potential dangers, especially if they involve malware that infects computers. Previous studies introduced botnet model detection focusing on binary class detection to recognize botnet activity and normal activity. Meanwhile, there are challenges to detecting specific botnet attack activities such as SPAM activities. This paper presents an approach utilizing ensemble multi-label classification for the detection of SPAM attacks executed by botnets. The proposed method involves four stages: data preparation, labeling, splitting, and ensemble classification. In the data preparation phase, binary encoding enhances feature representation, while the labeling process categorizes instances into normal, botnet attack (Non SPAM), and botnet SPAM attack for comprehensive analysis. Using the Stratified k-Fold approach in data splitting ensures balanced representation in training and testing sets to address dataset imbalances. Then, in the classification phase, this research combines a Decision Tree, Random Forest, k-nearest Neighbors, Naïve Bayes, and Logistic Regression algorithm with an ensemble “hard” voting strategy. The proposed model achieves the highest accuracy detection performance of 99.05%, demonstrating the effectiveness of the ensemble in detecting SPAM botnet activity. Additionally, the ensembles exhibit adaptability and robustness, offering administrators valuable insights for decision-making in managing attacks.
AB - Botnet SPAM activities on networks require effective management due to their potential dangers, especially if they involve malware that infects computers. Previous studies introduced botnet model detection focusing on binary class detection to recognize botnet activity and normal activity. Meanwhile, there are challenges to detecting specific botnet attack activities such as SPAM activities. This paper presents an approach utilizing ensemble multi-label classification for the detection of SPAM attacks executed by botnets. The proposed method involves four stages: data preparation, labeling, splitting, and ensemble classification. In the data preparation phase, binary encoding enhances feature representation, while the labeling process categorizes instances into normal, botnet attack (Non SPAM), and botnet SPAM attack for comprehensive analysis. Using the Stratified k-Fold approach in data splitting ensures balanced representation in training and testing sets to address dataset imbalances. Then, in the classification phase, this research combines a Decision Tree, Random Forest, k-nearest Neighbors, Naïve Bayes, and Logistic Regression algorithm with an ensemble “hard” voting strategy. The proposed model achieves the highest accuracy detection performance of 99.05%, demonstrating the effectiveness of the ensemble in detecting SPAM botnet activity. Additionally, the ensembles exhibit adaptability and robustness, offering administrators valuable insights for decision-making in managing attacks.
KW - Ensemble classification
KW - Information security
KW - Machine learning
KW - National security
KW - Network infrastructure
KW - Network security
KW - SPAM botnet detection
UR - https://www.scopus.com/pages/publications/105023495595
U2 - 10.1007/978-981-96-6718-5_6
DO - 10.1007/978-981-96-6718-5_6
M3 - Conference contribution
AN - SCOPUS:105023495595
SN - 9789819667178
T3 - Lecture Notes in Networks and Systems
SP - 65
EP - 77
BT - Advances in Distributed Computing and Machine Learning - Proceedings of ICADCML 2025
A2 - Kar, Binayak
A2 - Teng, Wei-Chung
A2 - Tripathy, Asis Kumar
A2 - Sahoo, Jyoti Prakash
A2 - Obaidat, Mohammad S.
PB - Springer Science and Business Media Deutschland GmbH
T2 - 6th International Conference on Advances in Distributed Computing and Machine Learning, ICADCML 2025
Y2 - 9 January 2025 through 10 January 2025
ER -