Botnet Detection Method Based on Artificial Intelligence

Botnet Detection Method Based on Artificial Intelligence
复制标题

DOI:
10.1109/dsc.2019.00080
复制
发表时间:
2019-06
期刊:
2019 IEEE Fourth International Conference on Data Science in Cyberspace (DSC)
影响因子:
--
通讯作者:
Zhihui Guo;Jin Peng;Jun Fu;Yexia Cheng;Cancan Chen
Zhihui Guo;Jin Peng;Jun Fu;Yexia Cheng;Cancan Chen
中科院分区:
其他
文献类型:
--
作者:
Zhihui Guo;Jin Peng;Jun Fu;Yexia Cheng;Cancan Chen

文献摘要

被引文献

相似文献

随着物联网的快速发展,新兴的僵尸网络攻击变得更加猖and和有害。为了检测僵尸网络,论文中提出了基于人工智能的方法,该方法检测僵尸网络中核心C&C服务器的域名。建立了相应的检测模型,并为算法提供了9种类型的特征。特别是,我们将发音特征和TLD功能应用于机器学习中,以提高僵尸网络检测的准确性。我们使用统计方法来降低误报率。统计方法的结果被馈回了语料库,因此机器学习模型的概括能力得到不断增强。在连续优化之后,最终模型的准确性可以达到99.38%,误报率为0.28%,在测试环境中,假负率为1.86%。同时,我们的检测方法还可以在4个月内从实际网络环境中有效检测到2000多个僵尸网络域名。
With the rapid development of the Internet of Things, the emerging botnet attacks have become more rampant and harmful. In order to detect botnet, the method based on artificial intelligence is proposed in the paper, which detects the domain name of the core C&C server in the botnet. The corresponding detection model is established and 9 types of features are given for the algorithm. Particularly, we apply the pronunciation features and TLD features into machine learning to improve the accuracy of botnet detection. We use statistical methods to reduce the false positive rate. The results of statistical method are fed back to the corpus, so that generalization ability of the machine learning model is continuously strengthened. After continuous optimization, the final model accuracy can reach up to 99.38%, the false positive rate is 0.28%, and the false negative rate is 1.86% in the testing environment. Meanwhile, our detection method can also effectively detect more than 2000 botnet C&C domain names from the real-world network environment in 4 months.