Botnet Detection Based on Anomaly and Community Detection
Botnet Detection Based on Anomaly and Community Detection
复制标题
DOI:
10.1109/tcns.2016.2532804
复制
发表时间:
2017-06
影响因子:
4.2
通讯作者:
Jing Wang;I. Paschalidis
中科院分区:
文献类型:
--
作者:
Jing Wang;I. Paschalidis
We introduce a novel two-stage approach for the important cybersecurity problem of detecting the presence of a botnet and identifying the compromised nodes (the bots), ideally before the botnet becomes active. The first stage detects anomalies by leveraging large deviations of an empirical distribution. We propose two approaches to create the empirical distribution: 1) a flow-based approach estimating the histogram of quantized flows and 2) a graph-based approach estimating the degree distribution of node interaction graphs, encompassing both Erdős-Rényi graphs and scale-free graphs. The second stage detects the bots using ideas from social network community detection in a graph that captures correlations of interactions among nodes over time. Community detection is performed by maximizing a modularity measure in this graph. The modularity maximization problem is nonconvex. We propose a convex relaxation, an effective randomization algorithm, and establish sharp bounds on the suboptimality gap. We apply our method to real-world botnet traffic and compare its performance with other methods.