Detecting Stealthy Botnets in a Resource-Constrained Environment using Reinforcement Learning

Detecting Stealthy Botnets in a Resource-Constrained Environment using Reinforcement Learning
复制标题

使用强化学习在资源受限的环境中检测隐形僵尸网络

DOI:
--
复制
发表时间:
2017
期刊:
MTD@CCS
影响因子:
--
通讯作者:
S. Jajodia
S. Jajodia
中科院分区:
--
文献类型:
--
作者:
S. Venkatesan;Massimiliano Albanese;Ankit Shah;R. Ganesan;S. Jajodia

文献摘要

被引文献

相似文献

现代僵尸网络可以通过以隐身方式运行而在网络系统中持续很长一段时间。尽管在僵尸网络预防、检测和缓解方面取得了进展,但隐形僵尸网络仍然对企业构成重大风险。此外,现有的企业级解决方案需要大量的资源来有效地运行,因此它们是不实用的。为了在资源受限的环境中解决这一重要问题,我们提出了一种基于强化学习的方法来优化和动态地部署有限数量的防御机制,即蜜罐和基于网络的检测器,在目标网络中。所提出的方法的最终目标是通过顺序决策过程最大化识别和删除的机器人数量来减少隐身僵尸网络的生命周期。我们提供了一个概念验证所提出的方法,并在模拟环境中研究其性能。实验结果表明,该方法在防御隐身僵尸网络方面具有良好的应用前景。
Modern botnets can persist in networked systems for extended periods of time by operating in a stealthy manner. Despite the progress made in the area of botnet prevention, detection, and mitigation, stealthy botnets continue to pose a significant risk to enterprises. Furthermore, existing enterprise-scale solutions require significant resources to operate effectively, thus they are not practical. In order to address this important problem in a resource-constrained environment, we propose a reinforcement learning based approach to optimally and dynamically deploy a limited number of defensive mechanisms, namely honeypots and network-based detectors, within the target network. The ultimate goal of the proposed approach is to reduce the lifetime of stealthy botnets by maximizing the number of bots identified and taken down through a sequential decision-making process. We provide a proof-of-concept of the proposed approach, and study its performance in a simulated environment. The results show that the proposed approach is promising in protecting against stealthy botnets.