Botnet Detection by Integrating Multiple Machine Learning Models
Thanawat Tejapijaya, Prarinya Siritanawan, Karin Sumongkayothin, Kazunori Kotani
2024
Abstract
Botnets are persistent and adaptable cybersecurity threats, displaying diverse behaviors orchestrated by various attacker groups. Their ability to operate stealthily on a massive scale poses challenges to conventional security monitoring systems like Security Information and Event Management (SIEM). In this study, we propose an integrated machine learning method to effectively identify botnet activities under different scenarios. Our approach involves using Shannon entropy for feature extraction, training individual models using random forest, and integrating them in various ways. To evaluate the effectiveness of our methodology, we compare various integrating strategies. The evaluation is conducted using unseen network traffic data, achieving a remarkable reduction in false negatives by our proposed method. The results demonstrate the potential of our integrating method to detect different botnet behaviors, enhancing cybersecurity defense against this notorious threat.
DownloadPaper Citation
in Harvard Style
Tejapijaya T., Siritanawan P., Sumongkayothin K. and Kotani K. (2024). Botnet Detection by Integrating Multiple Machine Learning Models. In Proceedings of the 10th International Conference on Information Systems Security and Privacy - Volume 1: ICISSP; ISBN 978-989-758-683-5, SciTePress, pages 366-373. DOI: 10.5220/0012317700003648
in Bibtex Style
@conference{icissp24,
author={Thanawat Tejapijaya and Prarinya Siritanawan and Karin Sumongkayothin and Kazunori Kotani},
title={Botnet Detection by Integrating Multiple Machine Learning Models},
booktitle={Proceedings of the 10th International Conference on Information Systems Security and Privacy - Volume 1: ICISSP},
year={2024},
pages={366-373},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0012317700003648},
isbn={978-989-758-683-5},
}
in EndNote Style
TY - CONF
JO - Proceedings of the 10th International Conference on Information Systems Security and Privacy - Volume 1: ICISSP
TI - Botnet Detection by Integrating Multiple Machine Learning Models
SN - 978-989-758-683-5
AU - Tejapijaya T.
AU - Siritanawan P.
AU - Sumongkayothin K.
AU - Kotani K.
PY - 2024
SP - 366
EP - 373
DO - 10.5220/0012317700003648
PB - SciTePress