HTTP-based Bontnet Detection Algorithm Based on Extreme Learning Machine

Yongfeng Gao · Journal of Lanzhou University of Arts and Science · 2014

At present,botnet has been one of the moset serious threats for Internet security.After more than10years evolution,most botnet prefers to use HTTP pcotocol rather than IRC pcotocol for bots' communication,which has caused many difficultis for botnet dectection and defense.After analysing the traffic trace produced by HTTP-based botnet,this paper has extracted some useful features such as TCP protocol statistical information,time interval of bot activity.Based on these features, this paper also proposed using ELM(Extreme Learning Machine)method for detecting HTTP-based botnet.The experiment results show that this method can identify some HTTP-based botnets from network traffic trace efficiently,such as BlackEnergry,Bobax.The comparison result with other algorithms(e.g.C4.5Decision Tree,SVM and BP Neural Network)also indicates that this method has higher true positive rates and less false positive rates.

Read the paper · More papers on PaperTik