Feature selection for detection of peer-to-peer botnet traffic
Pratik Narang, Jagan Mohan Reddy, Chittaranjan Hota · 2013
The use of anomaly-based classification of intrusions has increased significantly for Intrusion Detection Systems. Large number of training data samples and a good 'feature set' are two primary requirements to build effective classification models with machine learning algorithms. Since the amount of data available for malicious traffic will often be small compared to the available traces of benign traffic, extraction of 'good' features which enable detection of malicious traffic is a challenging area of work.