作者: Guilherme Henrique Ribeiro , Elaine R. de Faria Paiva , Rodrigo Sanches Miani
关键词: Flow network 、 Algorithm 、 Attack surface 、 Botnet 、 Evaluation strategy 、 Communications protocol 、 Data stream mining 、 Computer science 、 Cryptocurrency 、 Intrusion detection system
摘要: Recent botnet activities targeting IoT infrastructure and turning computing devices into cryptocurrency miners indicate an increase in the attack surface capabilities. These facts emphasize importance of investigating alternative methods for detecting botnets. One them is using stream mining algorithms to classify malicious network traffic. Although some initiatives seek adopt strategies detect botnets, several research topics still need be discussed. Our goal compare use single ensemble-based identify flows. Since obtaining examples flows could a hassle security managers, we also investigate whether ensembles reduce number labeled instances required update classification model. results that Ozaboost algorithm with prequential evaluation strategy outperforms other selected algorithms. We found characteristics (C&C communication protocol) requires less while maintains high performance.