On the Use of Machine Learning for Identifying Botnet Network Traffic

Matija Stevanovic, Jens Myrup Pedersen

Research output: Contribution to journalJournal articleResearchpeer-review

18 Citations (Scopus)
409 Downloads (Pure)

Abstract

During the last decade significant scientific efforts have been invested in the development of methods that could provide efficient and effective botnet detection. As a result, an array of detection methods based on diverse technical principles and targeting various aspects of botnet phenomena have been defined. As botnets rely on the Internet for both communicating with the attacker as well as for implementing different attack campaigns, network traffic analysis is one of the main means of identifying their existence. In addition to relying on traffic analysis for botnet detection, many contemporary approaches use machine learning techniques for identifying malicious traffic. This paper presents a survey of contemporary botnet detection methods that rely on machine learning for identifying botnet network traffic. The paper provides a comprehensive overview on the existing scientific work thus contributing to the better understanding of capabilities, limitations and opportunities of using machine learning for identifying botnet traffic. Furthermore, the paper outlines possibilities for the future development of machine
learning-based botnet detection systems.
Original languageEnglish
JournalJournal of Cyber Security and Mobility
Volume4
Issue number2 & 3
Number of pages32
ISSN2245-1439
DOIs
Publication statusPublished - 22 Jan 2016
EventCMI International Conference on Cyber Crime, Cyber Security, Privacy and Trust - AAU CPH, København, Denmark
Duration: 26 Nov 201527 Nov 2015

Conference

ConferenceCMI International Conference on Cyber Crime, Cyber Security, Privacy and Trust
LocationAAU CPH
Country/TerritoryDenmark
CityKøbenhavn
Period26/11/201527/11/2015

Keywords

  • Botnet detection
  • State of the art
  • Comparative analysis
  • Traffic analysis
  • Machine learning

Fingerprint

Dive into the research topics of 'On the Use of Machine Learning for Identifying Botnet Network Traffic'. Together they form a unique fingerprint.

Cite this