Botnet Detection Based on Anomaly and Community Detection

Botnet Detection Based on Anomaly and Community Detection
复制标题

DOI:
10.1109/tcns.2016.2532804
复制
发表时间:
2017-06
影响因子:
4.2
通讯作者:
Jing Wang;I. Paschalidis
Jing Wang;I. Paschalidis
中科院分区:
计算机科学3区
文献类型:
--
作者:
Jing Wang;I. Paschalidis

文献摘要

被引文献

相似文献

我们引入了一种新颖的两阶段方法来解决重要的网络安全问题,即检测僵尸网络的存在并识别受感染的节点(僵尸程序),最好是在僵尸网络变得活跃之前。第一阶段通过利用经验分布的大偏差来检测异常。我们提出了两种创建经验分布的方法:1)基于流的方法估计量化流的直方图,2)基于图的方法估计节点交互图的度分布,包括 Erdős-Rényi 图和无标度图。第二阶段使用图表中社交网络社区检测的想法来检测机器人,该图表捕获节点之间交互随时间的相关性。社区检测是通过最大化该图中的模块化度量来执行的。模块化最大化问题是非凸的。我们提出了凸松弛,一种有效的随机化算法,并在次优差距上建立了尖锐的界限。我们将我们的方法应用于现实世界的僵尸网络流量,并将其性能与其他方法进行比较。
We introduce a novel two-stage approach for the important cybersecurity problem of detecting the presence of a botnet and identifying the compromised nodes (the bots), ideally before the botnet becomes active. The first stage detects anomalies by leveraging large deviations of an empirical distribution. We propose two approaches to create the empirical distribution: 1) a flow-based approach estimating the histogram of quantized flows and 2) a graph-based approach estimating the degree distribution of node interaction graphs, encompassing both Erdős-Rényi graphs and scale-free graphs. The second stage detects the bots using ideas from social network community detection in a graph that captures correlations of interactions among nodes over time. Community detection is performed by maximizing a modularity measure in this graph. The modularity maximization problem is nonconvex. We propose a convex relaxation, an effective randomization algorithm, and establish sharp bounds on the suboptimality gap. We apply our method to real-world botnet traffic and compare its performance with other methods.